---
id: CVE-2026-49884
title: >-
  In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write
  due to an incorrect bounds check
summary: >-
  In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write
  due to an incorrect bounds check. This could lead to local escalation of
  privilege with no additional execution privileges needed. User interaction is
  not nee…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
  - android = 17.0
published: '2026-09-08'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T19:20:37.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49884'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-09-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
epss: 0.00096
epssPercentile: 0.00663
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T03:57:35.963652Z'
ingestedAt: '2026-09-08T19:08:49.641Z'
---

## Overview

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`
- `android = 17.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
