CVE-2026-0095: In l2c_fcr_clone_buf of l2c_fcr
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
- CVSS v3.1
- 8.0
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a heap corruption vulnerability caused by an integer overflow in the Android Bluetooth stack, specifically in the l2c_fcr_clone_buf function of l2c_fcr.cc. An attacker with a low-privilege account on the device and adjacent network access (such as Bluetooth radio range) can trigger the flaw without any victim interaction, corrupting memory inside the privileged Bluetooth process. Successful exploitation grants the attacker local escalation of privilege, giving them control at a higher permission level than their original account. No fix version has been published yet; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as upstream ships one.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built Android-derived container images, in both registry scans and CI pipeline checks. Any image carrying an affected version of the Android Bluetooth stack (Android 14, 15, 16, or 16-QPR2 lineage) is flagged automatically.
AvailableHarborGuard scores this CVE at 8.0 HIGH using the published CVSS v3.1 vector and weights it against each environment's compliance policy to determine urgency and routing. Findings are routed to the inbox or ticketing integration configured for the relevant team inside each customer organization.
AvailableBecause no upstream fix has been published, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Google publishes a fix version. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will be initiated without manual intervention once a fix is available.
Pending upstreamExploit Conditions
- Network reachabilityDetail
The attack requires adjacency to the target over a local wireless medium such as Bluetooth radio range or LAN; remote exploitation over the open internet is not possible.
- AuthenticationRequired
The attacker must hold at least a low-privilege account or session on the target device; unauthenticated access is not sufficient.
- Victim interactionNot required
No user action such as clicking a link or accepting a pairing request is needed; exploitation is fully attacker-driven.
- Attack complexityDetail
Exploit conditions are reliable and free of race conditions or special environmental requirements, making repeated attempts straightforward.
Blast Radius
- Attacker gains escalated privileges within the Android Bluetooth process, gaining permissions beyond their original low-privilege account.
- Controlled heap corruption allows reads of memory held by the privileged Bluetooth process, exposing sensitive data such as paired device keys or communication payloads.
- Heap corruption allows writes to memory in the privileged process, enabling tampering with Bluetooth communication state or injecting attacker-controlled data.
- The privileged Bluetooth process can be destabilized or crashed, disrupting all Bluetooth-dependent functionality on the device.
How HarborGuard Handles This
Available on HarborGuard: because no upstream fix exists for CVE-2026-0095 at this time, the platform monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild and, for customers who opt into auto-remediation, a regression test run and PR against affected workloads the moment Google publishes a fix. In the interim, customers can apply compensating controls within HarborGuard-managed environments: network-policy isolation to restrict Bluetooth-adjacent attack surfaces in containerized workloads, egress filtering to limit lateral movement if the Bluetooth process is compromised, and feature-flag gating to disable Bluetooth-dependent components where operationally feasible. The CVSS 8.0 HIGH rating and absence of a patch mean this advisory is surfaced at elevated priority in each environment's compliance queue until remediation becomes available.
- Google / Android16-qpr2 · 16 · 15 · 14
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H