CVE-2026-0124Disclosure(google / android)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-10); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-10: 4Mentions · 2026-03-11: 1Mentions · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 103-1003-1105-01
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-104
Disclosure3General1
2026-03-111
Disclosure1
2026-05-011
Patch1
Full discourse6 posts
  • xvonfers@xvonfers
    General

    CVE-2026-0114 https://www.cve.org/CVERecord?id=CVE-2026-0114 CVE-2026-0120 https://www.cve.org/CVERecord?id=CVE-2026-0120 CVE-2026-0122 https://www.cve.org/CVERecord?id=CVE-2026-0122 CVE-2026-0124 Reported by Christopher Wade https://www.cve.org/CVERecord?id=CVE-2026-0124

    Post summary

    The text lists four CVE identifiers with links to their CVE.org pages but provides no additional detail or context.

    13022102.5K
    4.9K followersView on X
  • romashkatea@romashka_tea
    Patch

    @Google @GooglePixel_US gateekeping the tools won't make vulnerabilities in the iROM less exploitable btw (CVE-2026-0124, b/308585798, reported in 2023, the reason why Google has disabled Pixel ROM Recovery on the Pixel 8a)

    Post summary

    The tweet notes that Google has disabled Pixel ROM Recovery on the Pixel 8a in response to CVE-2026-0124, serving as a vendor‑issued mitigation rather than an exploit disclosure.

    11030212
    39 followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-0124 PT-Identifier: PT-2026-24453 Vendor: Google Product: Android CVSS: 10.0 Credits: Christopher Wade Description: There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-0124 • https://source.android.com/docs/security/bulletin/pixel/2026/2026-03-01 #dbugs_vuln

    Post summary

    CVE-2026-0124 is a high‑severity out‑of‑bounds write vulnerability in Android that can lead to local privilege escalation without user interaction; the post provides a technical description and references but no evidence of active exploitation, PoC, or patch.

    0001288
    556 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Google Android (CVE-2026-0124) https://vuldb.com/?id.350260

    Post summary

    The text announces the addition of CVE-2026-0124 as a new vulnerability affecting Android, but offers no further technical or exploitation details.

    0000096
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0124 There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. … https://www.cve.org/CVERecord?id=CVE-2026-0124

    Post summary

    The text announces CVE‑2026‑0124, describing a missing bounds check that could lead to out‑of‑bound writes and local privilege escalation, but it offers no PoC, exploit code, active exploitation evidence, or patch information.

    00000138
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-0124: Google (CVSS: 10.0)... Perfect 10.0 CVSS score OOB write in Pixel devices = instant root with zero user interaction - Google's nightmare scenar... https://zerodaysignal.com/vulnerability/CVE-2026-0124 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑0124 as a severe (CVSS 10.0) zero‑day vulnerability that allows out‑of‑band writes on Pixel devices, potentially granting root without user interaction. No PoC, exploit code, or patch information is included.

    0000058
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---

Explore more