cbcvebase.
CVE-2025-26416
published 2025-09-02

CVE-2025-26416: In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of…

PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.36%
28.0th percentile
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformexternal_skia>= 13:0 < 13:2025-04-0113:2025-04-01
platformexternal_skia>= 14:0 < 14:2025-04-0114:2025-04-01
platformexternal_skia>= 15-next:0 < 15-next:2025-04-0115-next:2025-04-01
platformexternal_skia>= 15:0 < 15:2025-04-0115:2025-04-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered in `initializeSwizzler` of `SkBmpStandardCodec.cpp` — monitor for heap buffer overflow conditions in Android BMP image codec processing, particularly in Skia graphics library code paths handling BMP decoding.
  • No user interaction is required for exploitation — treat any remote delivery of malformed BMP image content to an Android 13/14/15 device as a potential exploitation vector for privilege escalation.
  • Affected AOSP versions are 13, 14, and 15 — prioritize patching and detection on devices running these versions; reference Android internal bug tracker ID A-388480622 for patch tracking.
  • ·Classified as CRITICAL severity EoP (Elevation of Privilege) by Android Security Bulletin; no additional execution privileges are needed and no user interaction is required, making this remotely exploitable without any preconditions.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.