Remote Code Execution Vulnerability in Android Products Affecting Privilege Escalation
CVE-2026-49919

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-49919?

In the function tt_face_colr_blend_layer of the ttcolr.c file, a potential vulnerability exists due to an integer overflow. This flaw allows remote code execution, enabling an attacker to escalate their privileges locally without requiring additional execution permissions. The exploitation of this vulnerability does not necessitate user interaction, which heightens the risk for affected systems.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.