In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation in Android AnnotationProcessor Enables Local Privilege Escalation |
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
cvssV3_1
|
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-09-08T18:05:55.342Z
Updated: 2026-09-08T19:36:46.603Z
Reserved: 2026-06-16T17:39:57.723Z
Link: CVE-2026-55273
Updated: 2026-09-08T19:36:38.276Z
Status : Awaiting Analysis
Published: 2026-09-08T19:18:01.500
Modified: 2026-09-08T20:17:35.050
Link: CVE-2026-55273
No data.