DIRAS TAKE
Treat this as urgent: public exploit code exists, so prioritize mitigating exposure and applying vendor guidance as soon as patches are released.
What is CVE-2026-28609?
An attacker with low privileges can trigger a memory corruption in Android's MatroskaExtractor to execute arbitrary code on affected devices; this is tracked as CVE-2026-28609. The flaw is an out-of-bounds write caused by improper casting in MatroskaExtractor.cpp and can lead to remote code execution without user interaction. Affected Android branches include 14.x, 15.x and 16.x (including 16 and 16-qpr2 builds); exploitation requires low privileges (PR:L) and does not require a user to interact with the device.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 16.x | 16-qpr2 | |
| 16.x | 16 | |
| 15.x | 15 | |
| 14.x | 14 |
Is CVE-2026-28609 being exploited?
Public exploit code is available.
How to fix CVE-2026-28609
- Restrict exposure: limit which apps and services can open Matroska media and block untrusted media sources.
- Apply vendor guidance and install vendor patches immediately when Google releases fixes for the listed branches.
- Monitor device logs and detection tools for crashes or unexpected behavior in media processing components.
- Harden devices by restricting installation of apps from untrusted sources and enforcing least privilege for apps that handle media.
Frequently asked questions
Is CVE-2026-28609 being actively exploited?
Public exploit code for CVE-2026-28609 is available, indicating an elevated risk of active exploitation.
Which Android versions are affected by CVE-2026-28609?
Android branches listed as affected include 14.x, 15.x and 16.x (notably 16 and 16-qpr2 builds).
Is there a patch for CVE-2026-28609?
No fixed versions are listed in the available data; follow Google's advisories and apply updates as soon as fixes are published.
Does CVE-2026-28609 require authentication?
Exploitation requires only low privileges (PR:L) and does not require user interaction, but it does not require elevated user authorization beyond that privilege level.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28609
- cve.org/CVERecord?id=CVE-2026-28609
- source.android.com/docs/security/bulletin/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026