
A carrier-restriction bypass in Android's oobconfig component — no privileges required, no user interaction, local access only. CVE-2026-0118, CVSS 8.4, published with the March 2026 Android Security Bulletin (patch level 2026-03-05). The oobconfig flaw is a logic error in Android's carrier config subsystem — CWE-693, protection mechanism failure. What makes it worth a second look is the PR:N on a local privilege escalation. Most LPEs require at least some foothold: an installed app, a low-priv shell, something. This one doesn't ask for elevated rights to begin with. In a mobile threat model — malicious APK, MDM-enrolled device, spyware-style deployment — that's a cleaner primitive than the CVSS vector alone suggests. The forecast puts exploitation probability at 0.26% at 90 days, with 99.9% of probability mass sitting in the Discovered state. No public PoC. No KEV listing. No confirmed in-the-wild exploitation. The HMM returns null for expectedDaysToMassExploitation — not evasive, just honest about the signal it has. The flat probability curve across the 30/60/90-day window says the threat-intelligence community hasn't seen weaponization signals, and that's directionally meaningful. The CVSS score doesn't capture the operational risk that actually matters here: Android's patch distribution is fragmented. Google shipped the bulletin; the distance from bulletin to device varies from days (Pixel) to never (end-of-support handsets). Enterprise MDM with enforced patch levels closes the exposure. BYOD and consumer OEM devices — Samsung, OnePlus, anything that isn't Pixel — are the residual surface. That fragmentation is the real story, and it doesn't show up anywhere in the CVE record. The MITRE mapping centers on T1068 (Exploitation for Privilege Escalation) as the primary technique, with T1548.002 adjacent given the protection mechanism bypass, and T1195.002 (malicious APK as delivery vector) as the plausible weaponization path if anyone bothers to build it. Verdict: patch in the normal sprint cycle. The PR:N/UI:N combination on a local vector is the one attribute worth watching — it makes weaponization cleaner if a PoC drops. KEV addition or public PoC would change the posture immediately; neither has happened. Not a tonight problem. A next-patch-cycle problem — unless your fleet has unmanaged Android handsets that haven't confirmed the March bulletin, in which case it's a this-week problem.
Post summary
The post discusses CVE-2026-0118, a local privilege‑escalation flaw with CVSS 8.4, noting no public PoC or active exploitation and highlighting the March 2026 patch already issued. It emphasizes the risk fragmentations across device fleets but deems it a non‑urgent issue pending the next patch cycle.

