CVE-2026-28662
Google · Android
A heap buffer overflow in the Android p2p_pd.c component allows for remote code execution via a specially crafted bootstrap request without requiring user interaction.
Executive summary
A heap buffer overflow vulnerability in Google Android allows adjacent attackers to achieve remote code execution on affected devices.
Vulnerability
The vulnerability exists in the p2p_process_prov_disc_bootstrap_req function within p2p_pd.c, where an out of bounds write occurs. This flaw allows an attacker with low privileges, positioned on an adjacent network, to execute code on the target system without any user interaction.
Business impact
Successful exploitation of this vulnerability permits an attacker to execute arbitrary code on the affected Android device, leading to full system compromise. Given the CVSS score of 8.0, this represents a significant security risk that could result in unauthorized access to sensitive user data, persistent malware installation, and total loss of device integrity.
Remediation
Immediate Action: Users and administrators should apply the latest Android security patches provided by Google as soon as they become available for their specific device model.
Proactive Monitoring: Security teams should monitor network traffic for anomalous peer to peer discovery requests or unexpected Wi-Fi direct connection attempts originating from unknown devices.
Compensating Controls: Disable Wi-Fi Direct features when not in use to reduce the attack surface, as this vulnerability is exploitable via adjacent network proximity.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a high risk to Android device security due to the potential for remote code execution. It is imperative that organizations and individuals monitor the official Google Android security bulletin for the release of a patch and apply the update immediately upon availability to mitigate the threat of potential exploitation.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.0 (3.1)
- Analyst report written