CVE-2026-55294: Buffer Overflow
Published Sep 8, 2026
·Updated
In ihevcdgettudatasize of ihevcdutils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Android libhevc
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2
Google Android=17.0
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue could allow local escalation of privilege without requiring additional execution privileges. No user interaction is needed for exploitation.
2
Is this vulnerability remotely exploitable?
The available information describes it as a local escalation-of-privilege issue. It does not state that remote exploitation is possible.