• PoC PUBLIC

CVE-2026-28609: remote code execution in Google Android

An attacker with low privileges can trigger a memory corruption in Android's MatroskaExtractor to execute arbitrary code on affected devices; this is tracked as CVE-2026-28609. The flaw is an out-of-bounds write caused by improper casting in MatroskaExtractor.cpp and can lead to remote code execution without user interaction. Affected Android branches include 14.x, 15.x and 16.x (including 16 and 16-qpr2 builds); exploitation requires low privileges (PR:L) and does not require a user to interact with the device.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00372
CWE
CWE-704
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: public exploit code exists, so prioritize mitigating exposure and applying vendor guidance as soon as patches are released.

What is CVE-2026-28609?

An attacker with low privileges can trigger a memory corruption in Android's MatroskaExtractor to execute arbitrary code on affected devices; this is tracked as CVE-2026-28609. The flaw is an out-of-bounds write caused by improper casting in MatroskaExtractor.cpp and can lead to remote code execution without user interaction. Affected Android branches include 14.x, 15.x and 16.x (including 16 and 16-qpr2 builds); exploitation requires low privileges (PR:L) and does not require a user to interact with the device.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
16.x16-qpr2
16.x16
15.x15
14.x14

Is CVE-2026-28609 being exploited?

Public exploit code is available.

How to fix CVE-2026-28609

  1. Restrict exposure: limit which apps and services can open Matroska media and block untrusted media sources.
  2. Apply vendor guidance and install vendor patches immediately when Google releases fixes for the listed branches.
  3. Monitor device logs and detection tools for crashes or unexpected behavior in media processing components.
  4. Harden devices by restricting installation of apps from untrusted sources and enforcing least privilege for apps that handle media.

Frequently asked questions

Is CVE-2026-28609 being actively exploited?

Public exploit code for CVE-2026-28609 is available, indicating an elevated risk of active exploitation.

Which Android versions are affected by CVE-2026-28609?

Android branches listed as affected include 14.x, 15.x and 16.x (notably 16 and 16-qpr2 builds).

Is there a patch for CVE-2026-28609?

No fixed versions are listed in the available data; follow Google's advisories and apply updates as soon as fixes are published.

Does CVE-2026-28609 require authentication?

Exploitation requires only low privileges (PR:L) and does not require user interaction, but it does not require elevated user authorization beyond that privilege level.

References