CVE-2026-49918: Integer Overflow
Published Sep 8, 2026
·Updated
In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android=16.0-qpr2
Google Android=17.0
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as a local escalation of privilege vulnerability. Exploitation requires local access, but no additional execution privileges are needed.
2
Does exploitation require user interaction?
No. User interaction is not needed for exploitation.
3
What is the underlying vulnerability class?
The issue involves integer overflow conditions that can cause out-of-bounds writes in multiple functions.