Description
In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An improper cast in MatroskaExtractor.cpp within Android’s Media framework leads to an out‑of‑bounds write. This memory corruption permits an attacker to execute arbitrary code on, representing a potential remote code execution flaw.

Affected Systems

The defect is present in Google Android; specific affected releases are not listed. Update all devices to the latest Android release that contains the MatroskaExtractor fix to eliminate the vulnerability.

Risk and Exploitability

The EPSS score is < 1% and the CVSS score is 8.8, yet the vulnerability is not currently in CISA's KEV catalog. The likely attack vector involves delivering a crafted Matroska file via Bluetooth, Wi‑Fi, or other media ingestion mechanisms, without requiring user action. Because no additional privileges are needed, any user of an affected device is at risk. Successful exploitation would give an attacker full control of the device, enabling data exfiltration, manipulation, or service disruption.

Generated by OpenCVE AI on September 11, 2026 at 02:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update that includes the MatroskaExtractor fix on all devices.
  • Configure devices to automatically install critical security patches or manually trigger an update if auto‑updates are disabled.
  • Restrict or disable Bluetooth and Wi‑Fi file‑sharing services for untrusted devices to reduce exposure to malicious media files.

Generated by OpenCVE AI on September 11, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Potential Out-of-Bounds Write in MatroskaExtractor Allowing Remote Code Execution
Weaknesses CWE-787

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-704
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Potential Out-of-Bounds Write in MatroskaExtractor Allowing Remote Code Execution
Weaknesses CWE-787

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:56:51.109Z

Reserved: 2026-03-02T19:11:06.138Z

Link: CVE-2026-28609

cve-icon Vulnrichment

Updated: 2026-09-10T14:56:46.831Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:53.053

Modified: 2026-09-15T14:17:03.557

Link: CVE-2026-28609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:15:10Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast