
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0010 is an out-of-bounds write vulnerability in the onTransact function of IDrmManagerService.cpp on Android, enabling local privilege escalation. It affects Google Android versions 14.0, 15.0, and 16.0. The vulnerability was published on March 2, 2026, with patches released via Google's Android Security Bulletin dated 2026-03-01. It carries a CVSS v3.1 base score of 8.4 (High), requiring no special privileges or user interaction for exploitation (Android Security Bulletin, Red Hat CVE).
The root cause is a missing bounds check in the onTransact function of IDrmManagerService.cpp, classified as CWE-787 (Out-of-bounds Write). An attacker with local access can send a crafted Binder IPC transaction to the DRM Manager Service, triggering a write beyond the allocated buffer boundary. Because no additional execution privileges are required and user interaction is not needed, any local process on the device can potentially trigger this condition to escalate privileges (Android Security Bulletin).
Successful exploitation allows an unauthenticated local attacker to escalate privileges on the affected Android device, achieving high confidentiality, integrity, and availability impact. An attacker could gain elevated code execution, potentially accessing sensitive user data, installing persistent malware, or fully compromising the device. The scope is limited to the affected device (unchanged scope), but privilege escalation could enable further abuse of device resources and data (Android Security Bulletin).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Android Security Bulletin). The EPSS score is approximately 0.009% (0.000090), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released patches addressing CVE-2026-0010 in the Android Security Bulletin dated 2026-03-01, covering Android versions 14.0, 15.0, and 16.0. Device owners and administrators should apply the March 2026 Android security update (patch level 2026-03-01 or later) as soon as it is available for their device. Samsung and other OEMs have also released corresponding security updates (Android Security Bulletin, Samsung Security). No configuration-based workarounds have been published; patching is the recommended remediation.
The CIS published an advisory noting that multiple vulnerabilities in the March 2026 Android update, including CVE-2026-0010, could allow for privilege escalation (CIS Advisory). GBHackers reported on the broader Android security update that fixed 129 flaws in the March 2026 bulletin (GBHackers). Community and media coverage has been routine, with no significant controversy or notable researcher commentary specific to this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."