GoogleCVE-2026-28583
Google Android: out-of-bounds write
High7.8CVE-2026-28583 · Published Sep 8, 2026 · updated Sep 15, 2026
In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= 16-qpr2 | No fix yet |
| <= 16 | No fix yet | |
| <= 15 | No fix yet | |
| <= 14 | No fix yet |
Details and references
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Google Android Wear: information disclosure | Critical10.0 | No fix yet |
| Sep 8 | Google Android XR: privilege escalation | Critical10.0 | No fix yet |
| Sep 8 | Google Android: use after free | High7.8 | No fix yet |
| Sep 8 | Google Android: race condition | High7.0 | No fix yet |
| Sep 8 | Google Android: privilege escalation | High7.8 | No fix yet |
| Sep 8 | Google Android: out-of-bounds read | High7.8 | No fix yet |