Description
In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists within the decodeAmr function of the Android media player, uncovered by a missing bounds check. This flaw allows an attacker to write beyond the intended memory area, potentially enabling execution of arbitrary code. The vulnerability is classified as a buffer copy without proper size validation, and the official assessment indicates that no additional privileges are required for exploitation.

Affected Systems

The flaw is present in the Android operating system supplied by Google. No specific OS versions or build variants are listed, so any Android installation that includes the current, unpatched media audio player code could be vulnerable until a patch is applied.

Risk and Exploitability

The assigned CVSS score of 8.0 reflects high exploitable risk, and the EPSS score of < 1% indicates a very low but nonzero probability that the vulnerability will be exploited. The weakness requires user interaction, likely through the playback of a crafted AMR media file, meaning that a malicious file needs to be opened or played by the user. Because it is not listed in the CISA KEV catalog, no public exploits are confirmed, but the high severity and need for ordinary user action suggest that the vulnerability could be leveraged in targeted attacks.

Generated by OpenCVE AI on September 20, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the newest Android security update from Google that addresses the decodeAmr buffer overflow.
  • Upgrade the device to the latest Android release that includes the vendor patch, verifying that the media audio player has been revised.
  • Restrict exposure by disabling or removing legacy applications that invoke AMR decoding, or block malicious media content via mobile security controls.

Generated by OpenCVE AI on September 20, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title DecodeAmr Buffer Overflow in Android Media Player

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android AMR Decoder Leading to Remote Code Execution

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in Android AMR Decoder Leading to Remote Code Execution

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:48.890Z

Reserved: 2026-06-16T17:52:49.256Z

Link: CVE-2026-55343

cve-icon Vulnrichment

Updated: 2026-09-15T20:41:20.342Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:21.600

Modified: 2026-09-21T17:20:08.437

Link: CVE-2026-55343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')