Out-of-bounds Read Vulnerability in VP9 Decoder by Google
CVE-2026-58699
Currently unrated
What is CVE-2026-58699?
The VP9 Decoder by Google contains a vulnerability within the Vp9DecEndOfStream function found in the vp9hwd_output.cc file, which is characterized by an improper bounds check. This flaw may allow local attackers to perform an out-of-bounds read, leading to potential privilege escalation without the need for additional execution privileges. Notably, exploitation does not require any user interaction, making this vulnerability a concern for system security.
Affected Version(s)
Android Android kernel