CVE-2026-0010
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0010 is an out-of-bounds write vulnerability in the onTransact function of IDrmManagerService.cpp on Android, enabling local privilege escalation. It affects Google Android versions 14.0, 15.0, and 16.0. The vulnerability was published on March 2, 2026, with patches released via Google's Android Security Bulletin dated 2026-03-01. It carries a CVSS v3.1 base score of 8.4 (High), requiring no special privileges or user interaction for exploitation (Android Security Bulletin, Red Hat CVE).

Technical details

The root cause is a missing bounds check in the onTransact function of IDrmManagerService.cpp, classified as CWE-787 (Out-of-bounds Write). An attacker with local access can send a crafted Binder IPC transaction to the DRM Manager Service, triggering a write beyond the allocated buffer boundary. Because no additional execution privileges are required and user interaction is not needed, any local process on the device can potentially trigger this condition to escalate privileges (Android Security Bulletin).

Impact

Successful exploitation allows an unauthenticated local attacker to escalate privileges on the affected Android device, achieving high confidentiality, integrity, and availability impact. An attacker could gain elevated code execution, potentially accessing sensitive user data, installing persistent malware, or fully compromising the device. The scope is limited to the affected device (unchanged scope), but privilege escalation could enable further abuse of device resources and data (Android Security Bulletin).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Android Security Bulletin). The EPSS score is approximately 0.009% (0.000090), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Google has released patches addressing CVE-2026-0010 in the Android Security Bulletin dated 2026-03-01, covering Android versions 14.0, 15.0, and 16.0. Device owners and administrators should apply the March 2026 Android security update (patch level 2026-03-01 or later) as soon as it is available for their device. Samsung and other OEMs have also released corresponding security updates (Android Security Bulletin, Samsung Security). No configuration-based workarounds have been published; patching is the recommended remediation.

Community reactions

The CIS published an advisory noting that multiple vulnerabilities in the March 2026 Android update, including CVE-2026-0010, could allow for privilege escalation (CIS Advisory). GBHackers reported on the broader Android security update that fixed 129 flaws in the March 2026 bulletin (GBHackers). Community and media coverage has been routine, with no significant controversy or notable researcher commentary specific to this CVE.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management