---
id: CVE-2026-56985
title: >-
  In multiple files, there is a possible way to obtain signatures due to type
  confusion
summary: >-
  In multiple files, there is a possible way to obtain signatures due to type
  confusion. This could lead to local escalation of privilege with no additional
  execution privileges needed. User interaction is not needed for exploitation.
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-441
vendor: google
product: android
affected:
  - android
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:48:05.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56985'
references:
  - url: 'https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01'
    label: dsap-vuln-management@google.com
tags:
  - nvd
  - cve.org
epss: 0.00098
epssPercentile: 0.00704
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T13:27:18.533926Z'
ingestedAt: '2026-09-15T18:41:59.158Z'
---

## Overview

In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
