CVE-2026-28618: Buffer Overflow
Published Sep 8, 2026
·Updated
In decfrmprepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
Where can I find the vendor security guidance for this issue?
The provided reference points to the Android Security Bulletin dated 2026-09-01.
2
Does the available information identify affected versions or fixed releases?
No. The supplied data does not list affected versions, patch levels, or fixed releases.