GoogleCVE-2026-49879
Google Android: out-of-bounds write
High8.8CVE-2026-49879 · Published Sep 8, 2026 · updated Sep 23, 2026
In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= 17 | No fix yet |
| <= 16-qpr2 | No fix yet | |
| <= 16 | No fix yet | |
| <= 15 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-787
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Google Android Wear: information disclosure | Critical10.0 | No fix yet |
| Sep 8 | Google Android XR: privilege escalation | Critical10.0 | No fix yet |
| Sep 8 | Google Android: use after free | High7.8 | No fix yet |
| Sep 8 | Google Android: race condition | High7.0 | No fix yet |
| Sep 8 | Google Android: privilege escalation | High7.8 | No fix yet |
| Sep 8 | Google Android: out-of-bounds read | High7.8 | No fix yet |