Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5556 articles · 213571 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-49921
google · android

CVE-2026-49921: In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote

Description

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
googleandroid17, 16-qpr2, 16, 15, 14

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googleandroidcert_advisory90%
lenovolenovo computercert_advisory90%

References

  • https://source.android.com/docs/security/bulletin/2026/2026-09-01

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] Android Patchday September 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-49921 | Google Android up to 17 heap-based overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedSep 8, 2026
Trending Score51
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85046EXPKEV
CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
Trending: 145
HIGHCVE-2026-87491EXPKEV
CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code in
Trending: 136
CRITICALCVE-2026-41157EXP
GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D
Trending: 65
CRITICALCVE-2026-58822
CVE-2026-58822: In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to
Trending: 51
HIGHCVE-2026-34192EXP
GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 8, 2026
Discovered by ZDM
Sep 8, 2026