Sceawere
Vulnerability Detail
CVE-2026-28667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Out-of-Bounds Read in rw_t5t.cc
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 4h ago
- Vendor
- Product
- Android
- Attack Type
- Information disclosure
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-05T19:17:20.410Z",
"pubdate": "2026-10-05T19:17:20.410Z",
"executiveSummary": "A critical out-of-bounds read vulnerability has been identified within multiple functions located in rw_t5t.cc. This flaw arises from a failure to perform adequate bounds checking during memory access operations.\nThe vulnerability enables a local attacker to perform unauthorized information disclosure, potentially exposing sensitive data resident in memory.\nExploitation does not require elevated privileges or user interaction, representing a significant risk to the integrity and confidentiality of the affected system's data.\nThe absence of a requirement for interaction or administrative access simplifies the attack vector, allowing local entities to trigger the memory access violation systematically.",
"technicalDetails": "The vulnerability stems from insufficient validation of input indices or length parameters when interacting with memory buffers within the rw_t5t.cc source file. In the identified functions, the code fails to ensure that requested read offsets remain within the allocated boundaries of the target memory structures.\nWhen a function processes a malformed or malicious payload, the lack of bounds verification allows the execution flow to perform read operations at memory locations preceding or succeeding the intended buffer.\nThe attack flow begins when an attacker provides input that influences the parameters governing memory access in the vulnerable functions. Because the system lacks a boundary condition check, the processor is instructed to access memory addresses outside the defined scope of the legitimate buffer. This operation reads unintended data into registers or output buffers, which may then be leaked to the attacker through system interfaces or logs.\nSince this is an out-of-bounds read, the immediate impact is the unauthorized disclosure of information stored in heap or stack memory adjacent to the vulnerable buffer. Depending on the memory layout and the state of the system at the time of exploitation, this information could include sensitive data, cryptographic keys, or pointers that might aid in further exploitation techniques, such as bypassing Address Space Layout Randomization (ASLR).\nThe vulnerability is characterized by a failure in input sanitization and verification logic. There is no requirement for authentication or user interaction to trigger this flaw, as the vulnerable functions are reachable by local processes. The reliance on implicit trust of input lengths or offsets within the affected functions is the primary root cause. The persistence of this issue across multiple functions within rw_t5t.cc suggests a systemic failure in enforcing consistent memory safety practices during the implementation of these components."
}