In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Heap Corruption in Android Bluetooth Process | |
| First Time appeared |
Google
Google android |
|
| Weaknesses | CWE-190 | |
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2026-06-01T22:56:23.705Z
Reserved: 2025-10-15T15:42:56.290Z
Link: CVE-2026-0095
Updated: 2026-06-01T22:56:12.885Z
Status : Received
Published: 2026-06-01T22:16:23.027
Modified: 2026-06-01T23:16:17.387
Link: CVE-2026-0095
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:45:25Z