Description
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
In plain language
AI Act nowThis is a memory-bug in Android’s GNSS image loading that can let a local attacker with powerful system privileges write past memory limits; only people who already have local, system-level access are at risk, but the bug is being reported as exploited in limited cases.
CVE-2026-58773 is a possible out-of-bounds write in Android GNSS image loading (link_load_gnss_image in link_device.c) that can be triggered locally by an attacker with System execution privileges, enabling local escalation of privilege without user interaction; exploitation has been reported as limited and targeted.
What to do now
- Check whether your organization uses Android devices that could be affected, and gather the exact Android build/version and device models.
- Check for any Android security updates released after 2026-09-01 for your specific device(s) and update to the latest available security patch.
- If you manage Android devices, confirm GNSS/location image loading components are present in your use case and that the devices are reachable only in controlled environments (not exposed to untrusted local apps/users).
- If you can’t upgrade quickly, isolate the affected devices from untrusted local access (restrict physical/USB access and lock down accounts) until a patch is applied.
- Monitor for unusual local activity: unexpected app behavior, privilege changes, or repeated crashes in GNSS/location-related components after device updates.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-58773 and every CVE in our database. Create a free account — no credit card required.
Create Free Account