Supply Chain Risk in Android's Annotation Processor by Google
CVE-2026-55273
Currently unrated
What is CVE-2026-55273?
The vulnerability arises within the AppendCommentLine function of AnnotationProcessor.cpp, where improper input validation creates a potential supply chain risk. This flaw allows for local escalation of privilege, as the exploitation does not require additional execution privileges or user interaction, making it a significant concern for affected Android versions.
Affected Version(s)
Android 17
Android 16-qpr2
Android 16