Out of Bounds Write Vulnerability in Android Product by Google
CVE-2026-49884

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-49884?

In the Android platform, a vulnerability exists in the rw_mfc_handle_read_op function within rw_mfc.cc, where improper bounds checking can lead to an out of bounds write scenario. This flaw may allow an attacker to escalate privileges locally without the need for additional execution rights, posing risks to the security integrity of the affected system. Exploitation does not require user interaction, making it potentially more dangerous.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.