Junglewise Threat Intelligence

CVE-2026-28618: Android System heap buffer overflow in dec_frm_prepare

CVE-2026-28618 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

A heap buffer overflow vulnerability exists in Android's System component (in the oapv.c module) that could allow an attacker to execute arbitrary code remotely without requiring any additional privileges or user interaction. This affects the core operating system and could lead to complete device compromise.

Technical details

The vulnerability is a heap buffer overflow caused by an out-of-bounds (OOB) write in the dec_frm_prepare function of oapv.c within the Android System component. The flaw allows remote code execution with no additional execution privileges required and does not need user interaction for exploitation. The attack vector is network-based, meaning an attacker can trigger this vulnerability remotely. Security patches addressing this issue have been released in the 2026-09-05 security patch level and later for affected Android versions (14, 15, 16, 16-qpr2, and 17).

Affected products

  • Google Android 14, 15, 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue

References

Related threats