ZeroHour

CVE-2026-58683

mass

Out-of-Bounds Write in Android IP Multimedia Subsystem Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

This vulnerability is an out-of-bounds write caused by improper input validation in the IP Multimedia Subsystem (IMS), the telephony subsystem that handles SIP-based services such as VoLTE, VoWiFi, and RCS messaging. The flaw was assigned by Google's Android/Pixel vulnerability management team, indicating it resides in the Android platform's IMS component on mobile devices. An attacker who already has low-level privileges (per the CVSS vector PR:L) can send crafted input to the IMS service over the network without any user interaction, corrupting memory and achieving remote code execution in the context of the IMS process with no additional execution privileges needed. Device users running affected Android builds are exposed, though the source data does not identify the specific patched versions. No public proof of concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation status is currently none known.

What to do: Patch to the latest Android security patch level as soon as Google publishes the fixed bulletin, prioritizing carrier-connected and BYOD fleets where IMS/VoLTE is active. Until patched, monitor device logs for crashes or anomalous behavior in the IMS/telephony process and restrict untrusted network access to device signaling paths. Enterprise admins should confirm via MDM that all managed Android devices are on the current patch level once it is released.

Affected
Google (Android) IP Multimedia Subsystem (Android platform component)
Estimated exposure
massPotentially millions to billions of Android devices ship the IMS component; the truly vulnerable subset is unknown — Android's active install base exceeds 2-3 billion devices and IMS is a standard telephony component on virtually all of them, but the affected version range is not stated so the vulnerable fraction cannot be narrowed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-20, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.