Out-of-bounds Read Vulnerability in Android System by Google
CVE-2026-58856

3.3LOW

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-58856?

In the DeprecatedCamera3StreamSplitter.cpp file, there's a flaw in the returnOutputBufferLocked function that potentially allows for an out-of-bounds read due to inadequate bounds checking. This vulnerability can lead to local information disclosure, as it does not require elevated permissions or any user interaction for exploitation. It poses a risk to personal data security within the affected Android versions.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.