---
id: CVE-2026-49937
title: >-
  In multiple functions of MessageQueueBase.h, there is a possible out of bounds
  read due to an incorrect bounds check
summary: >-
  In multiple functions of MessageQueueBase.h, there is a possible out of bounds
  read due to an incorrect bounds check. This could lead to local escalation of
  privilege with no additional execution privileges needed. User interaction is
  no…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
vendor: Google
product: Android
affected:
  - Android 17
  - Android 16-qpr2
  - Android 16
  - Android 15
  - Android 14
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:22.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49937'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-10-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-05T19:52:04.306811Z'
ingestedAt: '2026-10-05T19:30:59.986Z'
---

## Overview

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
