In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:* |
Tue, 02 Jun 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Heap Corruption in Android Bluetooth Process |
Mon, 01 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Heap Corruption in Android Bluetooth Process | |
| First Time appeared |
Google
Google android |
|
| Weaknesses | CWE-190 | |
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-06-01T21:14:55.239Z
Updated: 2026-06-02T03:56:18.869Z
Reserved: 2025-10-15T15:42:56.290Z
Link: CVE-2026-0095
Updated: 2026-06-01T22:56:12.885Z
Status : Analyzed
Published: 2026-06-01T22:16:23.027
Modified: 2026-06-03T17:00:44.710
Link: CVE-2026-0095
No data.