CVE-2026-55273: Input Validation
Published Sep 8, 2026
·Updated
In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
4 affected components
Unknown Unknown
Google Android=16.0
Google Android=16.0-qpr2
Google Android=17.0
Remediation
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What does an attacker need in order to exploit this issue?
The attacker needs local access. No additional execution privileges or user interaction are required.