CVE-2026-28583
massOut-of-Bounds Write in Android Camera Metadata Library Enables Local Privilege Escalation
An out-of-bounds write flaw (CWE-787) exists in the validate_camera_metadata_structure function of camera_metadata.c, Android's camera metadata validation code, and stems from a logical error in the code. A local attacker or already-running process needs no additional execution privileges to trigger the flaw by presenting malformed camera metadata, and no user interaction is required. Successful exploitation results in local escalation of privilege, allowing a low-privileged local component to gain higher privileges on the device. The issue affects Android devices running impacted builds of this camera metadata component, but no specific affected version ranges were provided in the available data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Apply the Android security update that addresses CVE-2026-28583 as delivered through monthly security bulletins or your device vendor's OTA updates, and confirm the patch via the device's security patch level after updating. Because exploitation requires local code execution with no user interaction, avoid installing untrusted local apps and prioritize updates on devices where low-privileged apps run unverified code. Check the Android Security Bulletin entry for this CVE to determine whether your specific device/OS version is listed as affected.
| Google Android (camera_metadata.c, camera metadata validation) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android
- Weakness
- CWE-693, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.