Sceawere

Vulnerability Detail

CVE-2026-58856UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Out-of-Bounds Read in DeprecatedCamera3StreamSplitter

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
2h ago
Vendor
Google
Product
Android
Attack Type
Elevation of privilege
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-05T19:17:24.967Z",
  "pubdate": "2026-10-05T19:17:24.967Z",
  "executiveSummary": "A vulnerability has been identified within the DeprecatedCamera3StreamSplitter.cpp source file, specifically located in the returnOutputBufferLocked function. The issue is classified as an out-of-bounds (OOB) read resulting from an inadequate bounds verification process during buffer management.\nThis vulnerability poses a significant risk to local system integrity, as it facilitates unauthorized information disclosure. An attacker can exploit this flaw without requiring additional execution privileges or user interaction, potentially leading to the leakage of sensitive data residing in memory adjacent to the target buffer.\nThe vulnerability affects the Android camera framework's legacy stream handling mechanism. Given the nature of the camera service—which often operates with system-level permissions—the inability to correctly validate buffer indices allows a malicious local actor to bypass standard memory protection boundaries. The impact is primarily categorized as an information leak, which may serve as a precursor to more complex chains of exploitation, such as circumventing address space layout randomization (ASLR) or extracting cryptographic material processed within the camera pipeline.",
  "technicalDetails": "The root cause of this vulnerability lies in the logic within returnOutputBufferLocked in DeprecatedCamera3StreamSplitter.cpp. The function fails to implement a robust validation check for the index or offset used to access the internal output buffer array. When the camera service attempts to return a buffer to the splitter, the code proceeds to access memory based on an index provided by the caller or derived from internal state, without confirming that this index falls within the allocated bounds of the buffer structure.\nThe exploitation flow begins when an attacker triggers a condition where the camera stream operations invoke returnOutputBufferLocked with an manipulated or unexpected buffer index. Because there is no check against the array size, the CPU performs a memory load from an address outside the intended segment. By crafting specific inputs that influence the internal state of the stream splitter, an attacker can influence which memory addresses are read.\nThis out-of-bounds read allows the attacker to read arbitrary memory contents that are mapped into the memory space of the process hosting the Camera3StreamSplitter. Since this process typically manages high-privilege media streams, the leaked memory may contain persistent data structures, frame data, or memory pointers that could facilitate further exploitation. Because the vulnerability is triggered during the routine handling of buffers within the Camera3 service, no special user interaction or external network exposure is required; it is strictly a local exploitation vector.\nThe lack of bounds verification represents a failure in defensive programming practices within the Android framework. The vulnerable component is part of the deprecated camera infrastructure, which may be less scrutinized than newer implementations. Successful exploitation results in the disclosure of information that should otherwise remain private to the camera process, effectively violating the memory isolation guarantees provided by the operating system kernel and the underlying hardware memory management unit."
}
CVE-2026-58856: Out-of-Bounds Read in DeprecatedCamera3StreamSplitter (LOW Severity, CVSS: 3.3) | Sceawere