cve-2026-49879

HIGH CVSS 8.8 opencve
Description

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Timeline
Published
2026-09-08 19:17 UTC
Last Modified
2026-09-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H nvd
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H opencve
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H vulnrichment
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-49879",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "17"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "16-qpr2"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "16"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "15"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "14"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "matching",
          "scores": [
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Android",
          "source": "cna",
          "vendor": "Google"
        },
        "product": "android",
        "vendor": "google"
      }
    ],
    "created": "2026-09-09T19:45:07.492480+00:00",
    "updated": "2026-09-11T01:00:09.676301+00:00",
    "vendors": [
      "google",
      "google$PRODUCT$android"
    ]
  },
  "epss": {
    "score": 0.00291
  },
  "mitre": {
    "cpes": [],
    "created": "2026-09-08T18:05:42.510000+00:00",
    "description": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/49xxx/CVE-2026-49879.json",
    "references": [
      "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
    ],
    "title": null,
    "updated": "2026-09-10T13:38:38.458000+00:00",
    "vendors": [],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
    ],
    "created": "2026-09-08T19:17:58.370000+00:00",
    "description": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-49879.json",
    "references": [
      "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
    ],
    "title": null,
    "updated": "2026-09-23T19:34:13.880000+00:00",
    "vendors": [
      "google",
      "google$PRODUCT$android"
    ],
    "weaknesses": [
      "CWE-787"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-08T18:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "added": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
              ],
              "removed": []
            },
            "type": "references"
          }
        ],
        "id": "838ba03a-eb82-4444-8f2d-1221bf173db4"
      },
      {
        "created": "2026-09-09T20:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Out‑of‑Bounds Write in Android Media Component Allows Remote Code Execution",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-190"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "a83183c9-a4b8-4a17-b2ff-517d9adce711"
      },
      {
        "created": "2026-09-10T09:30:00+00:00",
        "data": [
          {
            "details": [
              "google",
              "google$PRODUCT$android"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "google",
                "google$PRODUCT$android"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "2cb8f1f6-4d3a-4cc2-80f0-886229385d67"
      },
      {
        "created": "2026-09-10T14:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-787"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 8.8,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "651c668f-bd8a-4775-b044-d8eb9a045ef5"
      },
      {
        "created": "2026-09-10T17:00:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Out‑of‑Bounds Write in Android Media Component Allows Remote Code Execution"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-190"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "945574ee-38e8-4f9b-863c-bdbfee943810"
      },
      {
        "created": "2026-09-10T21:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Android Media Component Integer Overflow Enables Remote Code Execution",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "901a32ce-a9d4-4871-90d5-9cb0fc170090"
      },
      {
        "created": "2026-09-11T01:15:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Android Media Component Integer Overflow Enables Remote Code Execution"
            },
            "type": "title"
          }
        ],
        "id": "62209405-f2dc-4f2b-b374-e42b24677a12"
      },
      {
        "created": "2026-09-23T19:45:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          }
        ],
        "id": "ebe1f3df-f178-4c26-9b5d-46955d02c67b"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2026-09-08T18:05:42.510000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 8.8,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "vulnrichment"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00291
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2026-09-23T19:34:13.880000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "google",
        "google$PRODUCT$android"
      ],
      "providers": [
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-787"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-08T18:05:42.510000+00:00",
    "description": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-10T13:38:31.461000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/49xxx/CVE-2026-49879.json",
    "weaknesses": [
      "CWE-787"
    ]
  }
}
Enrichment data
View JSON API Download JSON