Impact
The Vp9DecodeFrameTag function in vp9hwd_headers.cc contains an off‑by‑one error that permits an out‑of‑bounds write when decoding a crafted VP9 stream. This memory corruption can be exploited without the attacker needing additional execution privileges, allowing the attacker to overwrite adjacent memory and thus elevate privilege on the device remotely.
Affected Systems
All Android devices that run firmware incorporating the vulnerable VP9 decoder component are affected. The issue is present in the Android operating system until the applicable security patch is applied. No specific Android version numbers are listed, so any device not yet updated after the September 2026 bulletin is potentially vulnerable.
Risk and Exploitability
The flaw receives a CVSS score of 8.8. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires no user interaction and can be performed remotely by delivering a malicious VP9 video stream to the target device, making it a serious risk for any Android device exposed to such streams.
OpenCVE Enrichment