Out-of-Bounds Write Vulnerability in Android NFA NFCEE
CVE-2026-49880

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-49880?

An out-of-bounds write vulnerability exists in multiple functions of nfa_nfcee_act.cc within Android's NFA NFCEE component. This flaw is attributed to a lack of proper bounds checking, which may allow local attackers to escalate their privileges on the device. Notably, this vulnerability can be exploited without requiring additional execution privileges or user interaction, making it a significant security concern for affected systems.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.