Description
In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

Based on the description, the vulnerability is an integer overflow in the convertCleanApertureToRect function of Heif can trigger a temporary denial of service without requiring user interaction or elevated privileges. The overflow occurs when processing HEIF files, potentially causing critical components that rely on the function to crash or become unresponsive, resulting in service interruption for the device or protected services.

Affected Systems

The flaw affects Android devices running Google Android where the HeifCleanAperture component is included. No specific version numbers are disclosed in the advisory, so all builds containing this code are potentially vulnerable until a patch is applied.

Risk and Exploitability

The issue is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low probability of exploitation, while the CVSS score of 4.3 points remote delivery of a specially crafted HEIF file to a device or service that decodes such files, and the impact is a temporary service interruption until a system restart or patch. Because no user interaction is required, the vulnerability can be triggered by an adversary with network access that can influence the decoding process.

Generated by OpenCVE AI on September 10, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the forthcoming Android security patch released by Google as soon as it becomes available
  • Restrict or sandbox the decoding of HEIF files from untrusted sources to prevent the overflow from affecting critical system components
  • Monitor device stability for unexpected crashes or repeated service restarts and report any incidents to Google for further analysis

Generated by OpenCVE AI on September 10, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Android HEIF Decoder Allows Remote Denial of Service

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in HeifCleanAperture Function Leading to Denial of Service
Weaknesses CWE-680

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in HeifCleanAperture Function Leading to Denial of Service
Weaknesses CWE-190
CWE-680

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:42:07.599Z

Reserved: 2026-05-12T17:37:06.748Z

Link: CVE-2026-45527

cve-icon Vulnrichment

Updated: 2026-09-10T15:42:00.553Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:57.910

Modified: 2026-09-24T15:18:58.043

Link: CVE-2026-45527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T22:00:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound