---
id: CVE-2026-0095
title: >-
  In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger
  controlled heap corruption within the privileged Bluetooth process due to an
  integer overflow
summary: >-
  In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger
  controlled heap corruption within the privileged Bluetooth process due to an
  integer overflow. This could lead to local escalation of privilege with no
  additional exe…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2026-06-01'
updated: '2026-07-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0095'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-06-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00107
epssPercentile: 0.01284
ingestedAt: '2026-07-23T08:15:14.578Z'
---

## Overview

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
