Description
In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Patch
AI Analysis

Impact

An out‑of‑bounds read occurs in the Vp9DecEndOfStream function of vp9hwd_output.cc. The incorrect bounds check allows a local attacker to read beyond the intended buffer limits, potentially exposing sensitive data or influencing program control flow. This flaw is classified as CWE‑125 and can elevate the attacker’s privilege level relative to the current user context without requiring additional execution privileges or user interaction.

Affected Systems

Devices running Google Android that incorporate the VP9 hardware‑decoder implementation are affected. The CNA does not specify particular OS releases or hardware revisions, so any Android device using the VP9 decoder component may be at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates a high‑severity vulnerability that can result in local privilege escalation. The EPSS score is less than 1%, suggesting a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. An attacker can supply a malicious VP9 stream via a media file or streaming application; the vulnerable decoder will perform an out‑of‑bounds read during playback, potentially leaking data or influencing program state to raise privileges.

Generated by OpenCVE AI on September 20, 2026 at 13:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android firmware update that fixes the VP9 decoder.
  • For devices where an update is not yet available, disable VP9 hardware acceleration or restrict applications that trigger VP9 decoding to limit exposure.
  • Regularly monitor Google Android security bulletins for new updates or patches and apply them promptly.

Generated by OpenCVE AI on September 20, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds read in VP9 decoder leads to local privilege escalation

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Android VP9 Decoder Out-of-Bounds Read Enables Local Privilege Escalation
Weaknesses CWE-788

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Android VP9 Decoder Out-of-Bounds Read Enables Local Privilege Escalation
Weaknesses CWE-788

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:23.105Z

Reserved: 2026-07-02T05:37:09.598Z

Link: CVE-2026-58699

cve-icon Vulnrichment

Updated: 2026-09-16T12:59:52.204Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:32.097

Modified: 2026-09-18T13:05:34.227

Link: CVE-2026-58699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses