CVE-2026-58822
CRITICALCVSS 9.8/10
Last modified
CVE-2026-58822 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed.
Description
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Android | 17; 16-qpr2; 16; 15; 14 |
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-58822?
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
How severe is CVE-2026-58822?
CVE-2026-58822 has a CVSS score of 9.8/10 (CRITICAL severity).
How do I fix CVE-2026-58822?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5878Incorrect security UI in Blink in Google Chrome prior to 147…4.3
- CVE-2026-5879Insufficient validation of untrusted input in ANGLE in Googl…8.8
- CVE-2026-5880Insufficient policy enforcement in browser UI in Google Chro…4.3
- CVE-2026-5881Policy bypass in LocalNetworkAccess in Google Chrome prior t…6.5
- CVE-2026-5882Incorrect security UI in Fullscreen in Google Chrome prior t…4.3
- CVE-2026-58820In multiple locations, there is a possible memory safety iss…7.8
- CVE-2026-58823In stpropnci_process_std of stpropnci_std.cc, there is a pos…7.8
- CVE-2026-5883Use after free in Media in Google Chrome prior to 147.0.7727…8.8
- CVE-2026-58839In forEachLine of MountRegistry.cpp, there is a possible out…7.8
- CVE-2026-5884Insufficient validation of untrusted input in Media in Googl…8.8
- CVE-2026-58846In kvm_iommu_map_sg of iommu.c, there is a possible use afte…7.8
- CVE-2026-58848In multiple functions of alloc.c, there is a possible unauth…7
Are you affected by CVE-2026-58822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
