---
id: CVE-2025-36936
title: >-
  In GetTachyonCommand of tachyon_server_common.h, there is a possible out of
  bounds write due to an integer overflow
summary: >-
  In GetTachyonCommand of tachyon_server_common.h, there is a possible out of
  bounds write due to an integer overflow. This could lead to local escalation
  of privilege with no additional execution privileges needed. User interaction
  is not…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
  - CWE-190
vendor: google
product: android
affected:
  - android
published: '2025-12-11'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36936'
references:
  - url: 'https://source.android.com/security/bulletin/pixel/2025-12-01'
    label: dsap-vuln-management@google.com
tags:
  - nvd
epss: 0.00078
epssPercentile: 0.00108
ingestedAt: '2026-09-30T17:13:20.765Z'
---

## Overview

In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
