Heap Buffer Overflow Vulnerability in Android by Google
CVE-2026-49882

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-49882?

The vulnerability involves a potential memory safety issue located in the rw_mfc_handle_read_op function of rw_mfc.cc, resulting in a heap buffer overflow. This flaw opens the door for attackers to execute arbitrary code remotely without requiring user interaction or additional privileges. Addressing this vulnerability is crucial for maintaining the integrity and security of devices running affected versions of Android.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.