Sceawere

Vulnerability Detail

CVE-2026-28667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Out-of-Bounds Read in rw_t5t.cc

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
4h ago
Vendor
Google
Product
Android
Attack Type
Information disclosure
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-10-05T19:17:20.410Z",
  "pubdate": "2026-10-05T19:17:20.410Z",
  "executiveSummary": "A critical out-of-bounds read vulnerability has been identified within multiple functions located in rw_t5t.cc. This flaw arises from a failure to perform adequate bounds checking during memory access operations.\nThe vulnerability enables a local attacker to perform unauthorized information disclosure, potentially exposing sensitive data resident in memory.\nExploitation does not require elevated privileges or user interaction, representing a significant risk to the integrity and confidentiality of the affected system's data.\nThe absence of a requirement for interaction or administrative access simplifies the attack vector, allowing local entities to trigger the memory access violation systematically.",
  "technicalDetails": "The vulnerability stems from insufficient validation of input indices or length parameters when interacting with memory buffers within the rw_t5t.cc source file. In the identified functions, the code fails to ensure that requested read offsets remain within the allocated boundaries of the target memory structures.\nWhen a function processes a malformed or malicious payload, the lack of bounds verification allows the execution flow to perform read operations at memory locations preceding or succeeding the intended buffer.\nThe attack flow begins when an attacker provides input that influences the parameters governing memory access in the vulnerable functions. Because the system lacks a boundary condition check, the processor is instructed to access memory addresses outside the defined scope of the legitimate buffer. This operation reads unintended data into registers or output buffers, which may then be leaked to the attacker through system interfaces or logs.\nSince this is an out-of-bounds read, the immediate impact is the unauthorized disclosure of information stored in heap or stack memory adjacent to the vulnerable buffer. Depending on the memory layout and the state of the system at the time of exploitation, this information could include sensitive data, cryptographic keys, or pointers that might aid in further exploitation techniques, such as bypassing Address Space Layout Randomization (ASLR).\nThe vulnerability is characterized by a failure in input sanitization and verification logic. There is no requirement for authentication or user interaction to trigger this flaw, as the vulnerable functions are reachable by local processes. The reliance on implicit trust of input lengths or offsets within the affected functions is the primary root cause. The persistence of this issue across multiple functions within rw_t5t.cc suggests a systemic failure in enforcing consistent memory safety practices during the implementation of these components."
}
CVE-2026-28667: Out-of-Bounds Read in rw_t5t.cc (MEDIUM Severity, CVSS: 5.5) | Sceawere