CVE-2026-0138
published 2026-06-16CVE-2026-0138: In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege…
PriorityP426
EPSS
0.07%
0.1th percentile
In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android lwis_io_buffer.c lwis_io_buffer_write out-of-bounds write
vuldb·2026-06-16
CVE-2026-0138 [CRITICAL] Google Android lwis_io_buffer.c lwis_io_buffer_write out-of-bounds write
A vulnerability identified as critical has been detected in Google Android. The affected element is the function lwis_io_buffer_write of the file lwis_io_buffer.c. This manipulation causes out-of-bounds write.
This vulnerability appears as CVE-2026-0138. The attack requires local access. There is no available exploit.
GHSA
In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption.
ghsa_unreviewed·2026-06-16
CVE-2026-0138 [HIGH] CWE-120 In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption.
In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published