DIRAS TAKE
Urgent: public exploit code is available and no patch is listed, so prioritize containment and monitoring for affected Android 16/17 devices and apply vendor guidance as soon as patches are released.
What is CVE-2026-28618?
A remote attacker can execute arbitrary code on Android by triggering a heap buffer overflow in dec_frm_prepare (CVE-2026-28618). The flaw affects Android branches/versions 17, 16, and 16-qpr2 as listed; exploitation does not require user interaction and the CVSS vector indicates network access and only low privileges are needed. Public exploit code exists, and a vendor patch is not yet available according to the facts provided, so vulnerable devices should be treated as high risk until fixed. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 17.x | 17 | |
| 16.x | 16-qpr2 | |
| 16.x | 16 |
Is CVE-2026-28618 being exploited?
Public exploit code is available.
How to fix CVE-2026-28618
- Follow the vendor advisory and install updates immediately when Google releases fixes for the affected Android 16 and 17 branches.
- Restrict network exposure of vulnerable devices and services to reduce attack surface.
- Monitor device and network logs for indicators of exploitation and unusual process crashes or memory corruption.
- Apply vendor-recommended mitigations and block or isolate devices that cannot be patched until fixes are deployed.
Frequently asked questions
Is CVE-2026-28618 being actively exploited?
Public exploit code is available for CVE-2026-28618; it is not listed in CISA's KEV catalog as of the provided date.
Which Android versions are affected by CVE-2026-28618?
Android versions affected include branch 17, branch 16, and 16-qpr2 as reported in the affected list.
Is there a patch for CVE-2026-28618?
No vendor-fixed versions are listed in the provided facts; a patch is not available according to the information given.
Does CVE-2026-28618 require authentication?
Exploitation of CVE-2026-28618 does not require user interaction and the CVSS vector indicates low privileges are sufficient rather than privileged authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28618
- cve.org/CVERecord?id=CVE-2026-28618
- source.android.com/docs/security/bulletin/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026