DIRAS TAKE
Treat this as high priority because the flaw allows unauthenticated, no-user-interaction remote code execution; prioritize reducing network exposure of Android devices and apply vendor mitigation guidance as it becomes available.
What is CVE-2026-58822?
Remote attackers can achieve remote code execution against Android by exploiting an improper cast in the ftsmooth.c functions; this is tracked as CVE-2026-58822. Affected releases include Android 14, 15, 16, 16-qpr2 and 17. The vulnerability requires no privileges and no user interaction to exploit, and the CVSS vector indicates network attackability, allowing unauthenticated remote code execution if an attacker can reach the vulnerable component.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 17.x | 17 | |
| 16.x | 16-qpr2 | |
| 16.x | 16 | |
| 15.x | 15 | |
| 14.x | 14 |
Is CVE-2026-58822 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-58822
- Restrict network exposure of affected Android devices and services to trusted networks.
- Apply any temporary mitigations recommended by Google as soon as they are published.
- Enable and review host and network detection for anomalous activity on devices running affected Android versions.
- Install fixes from the vendor immediately when patches for the affected Android builds become available.
Frequently asked questions
Is CVE-2026-58822 being actively exploited?
There are no public reports of exploitation of CVE-2026-58822 as of 2026-09-29.
Which Android versions are affected by CVE-2026-58822?
Android 14, 15, 16, 16-qpr2 and 17 are listed as affected by CVE-2026-58822.
Is there a patch for CVE-2026-58822?
No patch is available for CVE-2026-58822 as of 2026-09-29; follow vendor guidance and apply updates when Google releases fixes.
Does CVE-2026-58822 require authentication?
No; CVE-2026-58822 does not require privileges or user interaction and can be exploited without authentication if the attacker can reach the vulnerable component.
References
- nvd.nist.gov/vuln/detail/CVE-2026-58822
- cve.org/CVERecord?id=CVE-2026-58822
- source.android.com/docs/security/bulletin/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026