Description
In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out-of-bounds write caused by a_frm_prepare within oapv.c. The overflow can allow an attacker to overwrite arbitrary memory locations on the heap, potentially enabling the execution of malicious code. The description states that no additional privileges are required and that user interaction is not necessary, which indicates that execution can be performed remotely without the victim's cooperation.

Affected Systems

Affected products are all Android devices provided by Google that include the oapv.c component in their system libraries. Exact version numbers are not supplied in the advisory, so any device running the vulnerable Android release can be impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity flaw, while the EPSS score of <1% indicates a low probability of exploitation. The lack of a KEV listing means no confirmed exploitation is recorded at this time, but the nature of the heap overflow and the fact that it leads to remote code execution without user interaction represent a high-risk flaw. Attackers could trigger the overflow by delivering crafted data to the vulnerable module, making the vulnerability exploitable from a remote context once the data reaches the vulnerable function.

Generated by OpenCVE AI on September 10, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that includes the fix for the heap overflow in dec_frm_prepare.
  • Update your device -> About Phone -> System Update to ensure the patch is installed.
  • If the patch is unavailable, limit exposure by disabling any services or applications that trigger dec_frm_prepare, such as restricting LTE or Wi‑Fi management features, until a proper firmware update is released.

Generated by OpenCVE AI on September 10, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android System Function That Can Lead to Remote Code Execution

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android System Function That Can Lead to Remote Code Execution
Weaknesses CWE-122

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:38:29.909Z

Reserved: 2026-03-02T19:11:09.009Z

Link: CVE-2026-28618

cve-icon Vulnrichment

Updated: 2026-09-10T14:38:25.166Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:53.970

Modified: 2026-09-15T14:24:07.937

Link: CVE-2026-28618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses