Heap Buffer Overflow Vulnerability in Android Products by Google
CVE-2026-55294

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-55294?

A vulnerability exists in the ihevcd_get_tu_data_size function of ihevcd_utils.c, which may allow an out-of-bounds write due to a heap buffer overflow. This situation can result in local privilege escalation without requiring additional execution privileges or user interaction, effectively enabling attackers to exploit the vulnerability and gain unauthorized access.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.