HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-0095Published Modified CNA google_android

CVE-2026-0095: In l2c_fcr_clone_buf of l2c_fcr

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Metrics

CVSS v3.1
8.0
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a heap corruption vulnerability caused by an integer overflow in the Android Bluetooth stack, specifically in the l2c_fcr_clone_buf function of l2c_fcr.cc. An attacker with a low-privilege account on the device and adjacent network access (such as Bluetooth radio range) can trigger the flaw without any victim interaction, corrupting memory inside the privileged Bluetooth process. Successful exploitation grants the attacker local escalation of privilege, giving them control at a higher permission level than their original account. No fix version has been published yet; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as upstream ships one.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built Android-derived container images, in both registry scans and CI pipeline checks. Any image carrying an affected version of the Android Bluetooth stack (Android 14, 15, 16, or 16-QPR2 lineage) is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.0 HIGH using the published CVSS v3.1 vector and weights it against each environment's compliance policy to determine urgency and routing. Findings are routed to the inbox or ticketing integration configured for the relevant team inside each customer organization.

Available
Patch

Because no upstream fix has been published, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Google publishes a fix version. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will be initiated without manual intervention once a fix is available.

Pending upstream

Exploit Conditions

  • Network reachabilityDetail

    The attack requires adjacency to the target over a local wireless medium such as Bluetooth radio range or LAN; remote exploitation over the open internet is not possible.

  • AuthenticationRequired

    The attacker must hold at least a low-privilege account or session on the target device; unauthenticated access is not sufficient.

  • Victim interactionNot required

    No user action such as clicking a link or accepting a pairing request is needed; exploitation is fully attacker-driven.

  • Attack complexityDetail

    Exploit conditions are reliable and free of race conditions or special environmental requirements, making repeated attempts straightforward.

Blast Radius

  • Attacker gains escalated privileges within the Android Bluetooth process, gaining permissions beyond their original low-privilege account.
  • Controlled heap corruption allows reads of memory held by the privileged Bluetooth process, exposing sensitive data such as paired device keys or communication payloads.
  • Heap corruption allows writes to memory in the privileged process, enabling tampering with Bluetooth communication state or injecting attacker-controlled data.
  • The privileged Bluetooth process can be destabilized or crashed, disrupting all Bluetooth-dependent functionality on the device.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-0095 at this time, the platform monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild and, for customers who opt into auto-remediation, a regression test run and PR against affected workloads the moment Google publishes a fix. In the interim, customers can apply compensating controls within HarborGuard-managed environments: network-policy isolation to restrict Bluetooth-adjacent attack surfaces in containerized workloads, egress filtering to limit lateral movement if the Bluetooth process is compromised, and feature-flag gating to disable Bluetooth-dependent components where operationally feasible. The CVSS 8.0 HIGH rating and absence of a patch mean this advisory is surfaced at elevated priority in each environment's compliance queue until remediation becomes available.

See how HarborGuard automates this
Affected packages
  • Google / Android
    16-qpr2 · 16 · 15 · 14
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H