CVE-2026-58839
massOut-of-bounds read in Android MountRegistry enables local privilege escalation
A buffer overflow in the forEachLine function of MountRegistry.cpp causes an out-of-bounds read in a native Android system component (CWE-120). Per the CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N), the flaw is triggered locally by an attacker with low privileges and requires no user interaction. Successful exploitation leads to local escalation of privilege with high impact on confidentiality, integrity, and availability, yielding a severity score of 7.8 (High). Android devices running builds that include the affected code are potentially exposed, but the source data does not specify which Android versions or patch levels are impacted. Exploitation is not currently documented: the issue is absent from CISA KEV, EPSS assigns only a 0.1% probability of exploitation within 30 days, and no public proof-of-concept is known.
What to do: Apply the Android monthly security update from Google or your device vendor that fixes CVE-2026-58839 as soon as it is published, and verify that devices' Android security patch level reflects the fix. Because exploitation requires local code execution and no user interaction, restricting which low-privileged apps run on shared or sensitive devices reduces exposure, but no configuration workaround is known. Monitor the Android security bulletin for the definitive list of affected versions, since the provided data does not enumerate impacted releases.
| Google Android | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.