Description
In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Patch ASAP
AI Analysis

Impact

In multiple functions of XmpDataParser.java, an improper data sanitization logic flaw allows sensitive data to be read without additional execution privileges. The issue does not require user interaction and can be triggered by a locally trusted application or malicious file, leading to the disclosure of confidential information such as user preferences, media metadata or potentially credential data stored in the XMP format.

Affected Systems

The vulnerability affects Android devices manufactured by Google. No specific build numbering is cited in the advisory, so any Android installation that contains the vulnerable XmpDataParser.java module is potentially impacted, regardless of RAM or OS tier.

Risk and Exploitability

The flaw is local; an attacker must have access to the device and the ability to execute a malicious app or place a file that triggers XMP parsing. The CVSS score of 3.3 reflects a moderate impact on confidentiality. The EPSS score of less than 1% indicates a very low probability of exploitation, and the flaw is not listed in CISA KEV. Nonetheless, because the affected platform is widely deployed, the vulnerability warrants immediate attention.

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that addresses the XmpDataParser sanitization flaw.
  • If the device firmware cannot be updated, limit or remove applications that invoke the XMP parsing functionality until a patch is available.
  • Continuously monitor Android security bulletins for future updates and apply them promptly.

Generated by OpenCVE AI on September 10, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Thu, 10 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Data Sanitization in Android XmpDataParser Leads to Local Information Disclosure

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure in Android XMP Data Parsing
Weaknesses CWE-200

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure in Android XMP Data Parsing
Weaknesses CWE-200

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T16:23:05.262Z

Reserved: 2026-03-02T19:11:13.944Z

Link: CVE-2026-28638

cve-icon Vulnrichment

Updated: 2026-09-10T16:22:59.679Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:55.267

Modified: 2026-09-15T14:06:20.510

Link: CVE-2026-28638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-20

    Improper Input Validation