CVE-2026-25270: Out-of-bounds Write in Camera Driver
Published Oct 6, 2026
·Updated
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
Affected Software
1 affected component
Google Android Camera driver
Event History
Oct 6, 2026
CVE Published
via MITRE·06:29 AM
Data Sourced
via MITRE·06:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires high privileges and local access, according to the CVSS vector. The issue affects the Google Android Camera driver when it processes command buffer requests with invalid length parameters.
2
What impact could successful exploitation have?
The reported impact includes high confidentiality, integrity, and availability effects. Successful exploitation could therefore expose or alter data and disrupt the affected system.