Sceawere

Vulnerability Detail

CVE-2026-58835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Heap Buffer Overflow in cfg2prop

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
Google
Product
Android
Attack Type
Elevation of privilege
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-05T19:17:24.650Z",
  "pubdate": "2026-10-05T19:17:24.650Z",
  "executiveSummary": "A critical heap-based buffer overflow vulnerability exists within the cfg2prop function located in btif_storage.cc. This vulnerability allows for memory corruption during the processing of configuration properties.\nThe flaw permits an attacker to perform an out-of-bounds write, which may result in remote code execution (RCE) on the target system.\nThe vulnerability is characterized by its high severity, as it does not require user interaction, specialized privileges, or authentication to exploit.\nSuccessful exploitation compromises the integrity, confidentiality, and availability of the affected system by allowing arbitrary code execution within the context of the Bluetooth stack or associated process.\nGiven the nature of the Bluetooth stack's exposure, this vulnerability poses a significant risk to affected devices, potentially allowing for silent, zero-click remote compromise.",
  "technicalDetails": "The vulnerability originates in the cfg2prop function within the btif_storage.cc source file. The issue stems from insufficient bounds checking when copying configuration data into a heap-allocated buffer. When the function processes input properties, it fails to adequately validate the size of the source data relative to the allocated destination buffer, resulting in a heap-based buffer overflow.\nDuring execution, the cfg2prop function reads external or stored configuration data that is expected to be formatted according to specific internal structures. If a maliciously crafted configuration property is supplied, it can exceed the expected size of the destination heap allocation. Because the subsequent copy operation does not enforce strict length constraints, the operation writes past the memory boundary allocated for the buffer.\nThis out-of-bounds write facilitates the overwriting of adjacent heap objects. An attacker can leverage this memory corruption to overwrite critical structures such as function pointers, heap metadata, or object headers. By carefully grooming the heap layout, an attacker can control the flow of execution, redirecting program control to an attacker-supplied payload stored in memory.\nThe attack vector does not require user interaction, as the Bluetooth stack often processes configuration properties automatically upon device startup or during service initialization. Because this occurs within the system-level Bluetooth stack, the attacker gains the privileges of the Bluetooth process, which typically possesses significant system capabilities.\nExploitation proceeds in the following sequence: First, the attacker provides a specifically crafted configuration property to the target system. Second, the cfg2prop function processes this input, triggering an unsafe copy operation that overflows the destination buffer on the heap. Third, the overflow overwrites adjacent memory, effectively hijacking the control flow. Fourth, the redirected execution path allows the attacker to execute arbitrary code with elevated privileges, leading to a complete compromise of the Bluetooth component and potential escalation to further system access."
}
CVE-2026-58835: Heap Buffer Overflow in cfg2prop (HIGH Severity, CVSS: 8.8) | Sceawere