---
id: CVE-2026-49927
title: >-
  In multiple locations, there is a possible out of bounds write due to an
  integer overflow
summary: >-
  In multiple locations, there is a possible out of bounds write due to an
  integer overflow. This could lead to local escalation of privilege with no
  additional execution privileges needed. User interaction is not needed for
  exploitation.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: google
product: android
affected:
  - android = 16.0
  - android = 17.0
published: '2026-09-08'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:46:43.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49927'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-09-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
epss: 0.00096
epssPercentile: 0.00668
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T20:15:04.918434Z'
ingestedAt: '2026-09-08T19:08:49.641Z'
---

## Overview

In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 16.0`
- `android = 17.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
