CVE-2026-49880: Google Android vulnerability
Published Oct 5, 2026
·Updated
In multiple functions of nfanfceeact.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 5, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
The affected software identified in the available data is Google Android. The issue is local, so exposure depends on an attacker being able to execute code on the device.
2
What does an attacker need to exploit it?
An attacker needs local code execution but does not need additional execution privileges. No user interaction is required.
3
What is the likely impact of successful exploitation?
Successful exploitation could allow local escalation of privilege through an out-of-bounds write.