PT-2026-49797 · Google · Android

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-0138

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In lwis io buffer write of lwis io buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-0138

Affected Products

Android