Junglewise Threat Intelligence

CVE-2026-58822: FreeType ftsmooth memory safety issue in casting

CVE-2026-58822 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Google Android, The FreeType Project FreeType. Vendors: Google.

Executive brief

FreeType is a widely-used library for rendering fonts in applications, including Android and many desktop systems. A memory safety vulnerability in the font smoothing code can be exploited remotely to execute arbitrary code without requiring user interaction or special privileges, potentially compromising any system that processes untrusted font files.

Technical details

The vulnerability exists in multiple functions of ftsmooth.c in FreeType, where improper type casting creates a memory safety issue. This flaw allows an attacker to trigger remote code execution by supplying a specially crafted font file. No user interaction or elevated privileges are required for exploitation; simply processing the malicious font can trigger the vulnerability. The attack vector is network-based (via font file distribution or embedding), and the vulnerability affects FreeType library versions used across Android and other systems. Patches are available through Android security updates (2026-09-05 patch level and later) and corresponding FreeType releases.

Affected products

  • The FreeType Project FreeType <UNKNOWN>
  • Google Android before 2026-09-05 security patch level (Android 14, 15, 16, 16-qpr2, 17 affected)

Timeline

  • 2026-09-08: disclosed: CVE-2026-58822 published in NVD; Android Security Bulletin published
  • 2026-09-05: patched: Android security patch level 2026-09-05 and later address this vulnerability

References

Related threats