Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0095

Опубликовано: 01 июн. 2026
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*

EPSS

Процентиль: 1%
0.00107
Низкий

8 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8
github
2 месяца назад

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8
fstec
2 месяца назад

Уязвимость сценария l2c_fcr_clone_buf of l2c_fcr.cc операционных систем Android, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00107
Низкий

8 High

CVSS3

Дефекты

CWE-190