CVE-2026-58822: pre-auth remote code execution in Google Android

Remote attackers can achieve remote code execution against Android by exploiting an improper cast in the ftsmooth.c functions; this is tracked as CVE-2026-58822. Affected releases include Android 14, 15, 16, 16-qpr2 and 17. The vulnerability requires no privileges and no user interaction to exploit, and the CVSS vector indicates network attackability, allowing unauthenticated remote code execution if an attacker can reach the vulnerable component.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00382
CWE
CWE-704
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority because the flaw allows unauthenticated, no-user-interaction remote code execution; prioritize reducing network exposure of Android devices and apply vendor mitigation guidance as it becomes available.

What is CVE-2026-58822?

Remote attackers can achieve remote code execution against Android by exploiting an improper cast in the ftsmooth.c functions; this is tracked as CVE-2026-58822. Affected releases include Android 14, 15, 16, 16-qpr2 and 17. The vulnerability requires no privileges and no user interaction to exploit, and the CVSS vector indicates network attackability, allowing unauthenticated remote code execution if an attacker can reach the vulnerable component.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
17.x17
16.x16-qpr2
16.x16
15.x15
14.x14

Is CVE-2026-58822 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-58822

  1. Restrict network exposure of affected Android devices and services to trusted networks.
  2. Apply any temporary mitigations recommended by Google as soon as they are published.
  3. Enable and review host and network detection for anomalous activity on devices running affected Android versions.
  4. Install fixes from the vendor immediately when patches for the affected Android builds become available.

Frequently asked questions

Is CVE-2026-58822 being actively exploited?

There are no public reports of exploitation of CVE-2026-58822 as of 2026-09-29.

Which Android versions are affected by CVE-2026-58822?

Android 14, 15, 16, 16-qpr2 and 17 are listed as affected by CVE-2026-58822.

Is there a patch for CVE-2026-58822?

No patch is available for CVE-2026-58822 as of 2026-09-29; follow vendor guidance and apply updates when Google releases fixes.

Does CVE-2026-58822 require authentication?

No; CVE-2026-58822 does not require privileges or user interaction and can be exploited without authentication if the attacker can reach the vulnerable component.

References