Junglewise Threat Intelligence

CVE-2026-58699: Android VP9 decoder out-of-bounds read in vp9hwd_output.cc

CVE-2026-58699 · Severity: high · CVSS 8.4 · Published 2026-09-15

Executive brief

Android's VP9 video decoder contains an out-of-bounds read vulnerability in the vp9hwd_output.cc file due to an incorrect bounds check. A local attacker can exploit this flaw to escalate privileges on affected Pixel devices without requiring special permissions or user interaction, potentially gaining full device control.

Technical details

The vulnerability is an out-of-bounds read in the Vp9DecEndOfStream function within vp9hwd_output.cc, caused by an incorrect bounds check in the VP9 decoder component. The flaw allows local code execution with no additional privileges needed, making it a privilege escalation vector. Attack is local in scope and requires no user interaction. The vulnerability is addressed in Android security patch level 2026-09-05 or later.

Affected products

  • Google Pixel <2026-09-05

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Addressed in Android security patch level 2026-09-05

References

Related threats