CVE-2026-28664: Security vulnerability
Published Sep 8, 2026
·Updated
In WriteImageToDisk of runtimeimage.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
Which versions or configurations should be treated as affected?
The available information does not identify affected versions, device models, or configuration conditions. The referenced source is an Android security bulletin, but the supplied data does not provide component-specific scope.
2
What access does an attacker need before exploitation?
This is described as a local privilege-escalation issue. Exploitation does not require user interaction or additional execution privileges.
3
Is a workaround available if patching cannot be completed immediately?
No workaround, mitigation, or fixed version is provided in the supplied information.