Out-of-bounds Read Vulnerability in VP9 Decoder by Google
CVE-2026-58699

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-58699?

The VP9 Decoder by Google contains a vulnerability within the Vp9DecEndOfStream function found in the vp9hwd_output.cc file, which is characterized by an improper bounds check. This flaw may allow local attackers to perform an out-of-bounds read, leading to potential privilege escalation without the need for additional execution privileges. Notably, exploitation does not require any user interaction, making this vulnerability a concern for system security.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.