Description
In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in several functions within "rw_t5t.cc" where a bounds check is omitted, allowing an out‑of‑bounds read. This flaw can expose confidential data located past the intended buffer and does so without requiring elevated privileges or any user interaction. The impact is strictly the potential to read local memory data that should remain inaccessible to the executing process.

Affected Systems

The affected product is Google Android. Affected components include the "rw_t5t.cc" source files; specific device models or OS versions are not listed in the advisory, so any Android build that includes these functions may be vulnerable.

Risk and Exploitability

The CVE carries no EPSS score and is not catalogued in CISA KEV, indicating a current lack of widespread exploitation reports. The attack vector is local and requires no additional execution privileges or user action. The severity depends on the sensitivity of the disclosed data; while the vulnerability does not enable privilege escalation or remote code execution, it represents a notable risk for privacy and integrity if exploited on a target device.

Generated by OpenCVE AI on October 5, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Android updates or security patches released by Google that address this out‑of‑bounds read in rw_t5t.cc
  • If a patch is not yet available, audit the affected functions and apply a bounds check before any memory read operations
  • Restrict privileged access to the components that use rw_t5t.cc and consider disabling or isolating the vulnerable functionality until remediation is in place

Generated by OpenCVE AI on October 5, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Out-of-Bounds Read in Android rw_t5t.cc
Weaknesses CWE-20

Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-10-05T18:23:43.678Z

Reserved: 2026-03-02T19:11:24.242Z

Link: CVE-2026-28667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:20.410

Modified: 2026-10-05T19:17:20.410

Link: CVE-2026-28667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:30:21Z

Weaknesses
  • CWE-20

    Improper Input Validation