Junglewise Threat Intelligence

CVE-2026-28638: Android XmpDataParser improper data sanitization leading to local information disclosure

CVE-2026-28638 · Severity: low · CVSS 3.3 · Published 2026-09-08

Executive brief

A logic error in Android's XmpDataParser component allows an attacker to bypass data sanitization checks and read sensitive information from device memory without requiring special privileges or user interaction. This could expose private user data such as photos, documents, or other sensitive files stored on the device.

Technical details

The vulnerability exists in multiple functions of XmpDataParser.java due to improper data sanitization caused by a logic error in the code. The flaw allows local information disclosure without requiring additional execution privileges. No user interaction is needed for exploitation. The vulnerability affects multiple Android versions, and patches are available in Android security patch level 2026-09-05 or later, with updates distributed through AOSP to affected Android versions 14 through 17.

Affected products

  • Google Android 14, 15, 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed
  • 2026-09-05: patched

References

Related threats