CVE-2026-58683
massOut-of-Bounds Write in Android IP Multimedia Subsystem Enables Remote Code Execution
This vulnerability is an out-of-bounds write caused by improper input validation in the IP Multimedia Subsystem (IMS), the telephony subsystem that handles SIP-based services such as VoLTE, VoWiFi, and RCS messaging. The flaw was assigned by Google's Android/Pixel vulnerability management team, indicating it resides in the Android platform's IMS component on mobile devices. An attacker who already has low-level privileges (per the CVSS vector PR:L) can send crafted input to the IMS service over the network without any user interaction, corrupting memory and achieving remote code execution in the context of the IMS process with no additional execution privileges needed. Device users running affected Android builds are exposed, though the source data does not identify the specific patched versions. No public proof of concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation status is currently none known.
What to do: Patch to the latest Android security patch level as soon as Google publishes the fixed bulletin, prioritizing carrier-connected and BYOD fleets where IMS/VoLTE is active. Until patched, monitor device logs for crashes or anomalous behavior in the IMS/telephony process and restrict untrusted network access to device signaling paths. Enterprise admins should confirm via MDM that all managed Android devices are on the current patch level once it is released.
| Google (Android) IP Multimedia Subsystem (Android platform component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-20, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.