• PoC PUBLIC

CVE-2026-28618: remote code execution in Google Android

A remote attacker can execute arbitrary code on Android by triggering a heap buffer overflow in dec_frm_prepare (CVE-2026-28618). The flaw affects Android branches/versions 17, 16, and 16-qpr2 as listed; exploitation does not require user interaction and the CVSS vector indicates network access and only low privileges are needed. Public exploit code exists, and a vendor patch is not yet available according to the facts provided, so vulnerable devices should be treated as high risk until fixed.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00375
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available and no patch is listed, so prioritize containment and monitoring for affected Android 16/17 devices and apply vendor guidance as soon as patches are released.

What is CVE-2026-28618?

A remote attacker can execute arbitrary code on Android by triggering a heap buffer overflow in dec_frm_prepare (CVE-2026-28618). The flaw affects Android branches/versions 17, 16, and 16-qpr2 as listed; exploitation does not require user interaction and the CVSS vector indicates network access and only low privileges are needed. Public exploit code exists, and a vendor patch is not yet available according to the facts provided, so vulnerable devices should be treated as high risk until fixed. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
17.x17
16.x16-qpr2
16.x16

Is CVE-2026-28618 being exploited?

Public exploit code is available.

How to fix CVE-2026-28618

  1. Follow the vendor advisory and install updates immediately when Google releases fixes for the affected Android 16 and 17 branches.
  2. Restrict network exposure of vulnerable devices and services to reduce attack surface.
  3. Monitor device and network logs for indicators of exploitation and unusual process crashes or memory corruption.
  4. Apply vendor-recommended mitigations and block or isolate devices that cannot be patched until fixes are deployed.

Frequently asked questions

Is CVE-2026-28618 being actively exploited?

Public exploit code is available for CVE-2026-28618; it is not listed in CISA's KEV catalog as of the provided date.

Which Android versions are affected by CVE-2026-28618?

Android versions affected include branch 17, branch 16, and 16-qpr2 as reported in the affected list.

Is there a patch for CVE-2026-28618?

No vendor-fixed versions are listed in the provided facts; a patch is not available according to the information given.

Does CVE-2026-28618 require authentication?

Exploitation of CVE-2026-28618 does not require user interaction and the CVSS vector indicates low privileges are sufficient rather than privileged authentication.

References