CVE-2026-49921: pre-auth remote code execution in Google Android

An attacker can achieve remote code execution on Android devices by exploiting a heap buffer overflow. CVE-2026-49921 is a memory safety flaw (CWE-122) that can lead to full code execution without any additional privileges; user interaction is not required. Affected branches include Android 14, 15, 16 (including 16-qpr2) and 17. Exploitation requires remote access to a vulnerable service or interface on the device; no account or user click is needed according to the reported details.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00386
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: this is a critical, remote code execution bug that requires no user interaction, so prioritize mitigations and prepare to deploy vendor patches when available.

What is CVE-2026-49921?

An attacker can achieve remote code execution on Android devices by exploiting a heap buffer overflow. CVE-2026-49921 is a memory safety flaw (CWE-122) that can lead to full code execution without any additional privileges; user interaction is not required. Affected branches include Android 14, 15, 16 (including 16-qpr2) and 17. Exploitation requires remote access to a vulnerable service or interface on the device; no account or user click is needed according to the reported details. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
17.x17
16.x16-qpr2
16.x16
15.x15
14.x14

Is CVE-2026-49921 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-49921

  1. Restrict network exposure of Android devices and block untrusted network access.
  2. Apply any vendor guidance and install security updates from Google as soon as they are released.
  3. Disable unnecessary services and interfaces on affected devices to reduce attack surface.
  4. Monitor device logs and behaviour for signs of compromise and investigate anomalies immediately.

Frequently asked questions

Is CVE-2026-49921 being actively exploited?

There are no public reports of exploitation of CVE-2026-49921 as of 2026-09-29.

Which Android versions are affected by CVE-2026-49921?

Android branches listed as affected include 14, 15, 16 (including 16-qpr2) and 17.

Is there a patch for CVE-2026-49921?

No fixed versions are listed; apply Google's updates and vendor guidance as soon as patches are published.

Does CVE-2026-49921 require authentication?

No — the vulnerability can lead to remote code execution without user interaction or additional privileges according to the reported information.

References