Out of Bounds Write Vulnerability in EfwApTransport of Android Products
CVE-2026-0123
8.4HIGH
What is CVE-2026-0123?
The vulnerability arises in the EfwApTransport component of the Android operating system due to a lack of proper bounds checking in the ProcessRxRing function. This flaw can allow attackers to perform an out of bounds write, potentially enabling them to escalate their privileges locally without the need for any additional execution rights. No user interaction is required for the exploitation of this vulnerability, making it a significant concern for affected Android versions.
Affected Version(s)
Android Android kernel