Race Condition Vulnerability in alloc.c Affects Android Platform
CVE-2026-58848

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-58848?

The vulnerability arises from a race condition in multiple functions of alloc.c within the Android platform, allowing potential unauthorized read and write operations. This could lead to local privilege escalation, enabling an attacker to gain higher-level permissions without the necessity for additional execution privileges or user interaction. The issue poses significant risks to the integrity and security of the Android environment, highlighting the need for prompt remediation.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.