CVE-2026-56942
massOut-of-Bounds Write in Android VP9 Decoder ReadTileInfo Enables Remote Code Execution
An out-of-bounds write (CWE-787) exists in the ReadTileInfo function of vp9hwd_headers.cc, a component of the VP9 video decoding path in Google's Android media stack, caused by a missing bounds check when parsing tile information in malformed VP9 video streams. Because VP9 content is commonly decoded when rendering web video, the flaw can be triggered remotely by an attacker who gets a crafted video file to a target device (e.g., via a web page, link, or media message) with no user interaction beyond normal delivery and no additional privileges required. Successful exploitation allows full compromise of confidentiality, integrity, and availability of the affected process (CVSS 3.1: 8.8, high), which in Android media pipelines typically means code execution within a sandboxed media/codec process that can then be chained for privilege escalation. It was assigned by Google's Android vulnerability management CNA, indicating Android (and OEM Android builds incorporating this decoder component) is the affected platform; specific fixed versions were not provided in the available data. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not known to have occurred in the wild.
What to do: Apply the Android security update that includes the fix for this CVE as soon as the relevant monthly Android Security Bulletin is released, since the flaw is remotely triggerable through ordinary media playback. Enterprises should inventory Android fleets (especially older or lesser-known OEM devices with slow patch cadences) and verify each device's security patch level. Until patched, users can reduce risk by avoiding playback of untrusted or unsolicited VP9-encoded video content from web pages and messaging apps.
| Google Android (VP9 hardware/software decoder component, file vp9hwd_headers.cc) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.