Junglewise Threat Intelligence

CVE-2026-58839: Android MountRegistry buffer overflow in forEachLine

CVE-2026-58839 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Google Android. Vendors: Google.

Executive brief

Android's MountRegistry component contains a buffer overflow vulnerability that allows an attacker with local access to read data outside of allocated memory boundaries. This could enable an attacker to escalate their privileges without needing additional permissions, potentially gaining full device control and access to sensitive user data.

Technical details

The vulnerability is an out-of-bounds read due to a buffer overflow in the forEachLine function of MountRegistry.cpp. The flaw allows a local attacker to read memory outside intended buffer boundaries, which can be exploited to escalate privileges on the affected device. No additional execution privileges are required and user interaction is not needed for exploitation. The issue affects multiple Android versions, with patches available in AOSP versions 14, 15, 16, 16-qpr2, and 17.

Affected products

  • Google Android 14, 15, 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed
  • 2026-09-01: patched

References

Related threats