Android-x86: 23 High Severity Vulnerabilities Disclosed Together on October 5, 2026
Key findings • 23 vulnerabilities disclosed simultaneously for Android-x86 on October 5, 2026. • Multiple High severity flaws allow for privilege escalation and code execution. • Common v…

Key findings
- 23 vulnerabilities disclosed simultaneously for Android-x86 on October 5, 2026.
- Multiple High severity flaws allow for privilege escalation and code execution.
- Common vulnerabilities include missing bounds checks, type confusion, and permission bypasses.
- Several CVEs involve out-of-bounds writes/reads and heap buffer overflows.
- No user interaction is required for exploitation of most vulnerabilities.
On October 5, 2026, a batch of 23 vulnerabilities was disclosed for Android-x86, a project that brings the Android operating system to PCs. The vulnerabilities, all disclosed on the same day, span a range of severity levels, with a significant number classified as High. These flaws primarily involve privilege escalation and code execution, posing a substantial risk to users if left unpatched.
Several vulnerabilities stem from common programming errors such as missing bounds checks, type confusion, and improper input validation. For instance, CVE-2026-58865 and CVE-2026-55265, both rated High and Medium respectively, are due to missing bounds checks in PduParser.java, potentially leading to denial of service. Similarly, CVE-2026-58856, a Low severity vulnerability, involves an out-of-bounds read due to a missing bounds check in DeprecatedCamera3StreamSplitter.cpp, leading to local information disclosure.
A notable theme among the High severity vulnerabilities is privilege escalation. CVE-2026-58880, for example, is a race condition in btif_rc.cc that could lead to local privilege escalation. CVE-2026-58854 involves memory corruption due to type confusion, also leading to local privilege escalation. Furthermore, CVE-2026-58835, a High severity flaw, is a heap buffer overflow in btif_storage.cc that could result in remote code execution. CVE-2026-55280, another High severity vulnerability, is caused by uninitialized data, potentially leading to remote privilege escalation.
Permission bypass vulnerabilities are also present in this batch. CVE-2026-58841, a High severity flaw, arises from a logic error in VirtualAudioControllerTest.java, allowing for local privilege escalation. CVE-2026-55270, a High severity vulnerability, is a confused deputy issue in dialInternal, enabling local privilege escalation. CVE-2026-45524, also High severity, is a sandbox escape due to a missing permission check in WifiPermissionsUtil.java, leading to local privilege escalation. CVE-2026-28647 and CVE-2026-28641, both High severity, are logic errors in DeviceAdminAppsPreferenceController.java and ApplicationActionButtonsPreferenceController.java respectively, resulting in local privilege escalation. CVE-2026-28640, another High severity vulnerability, is due to improper input validation in CredentialStorageActivity.java, leading to local privilege escalation.
Other vulnerabilities include out-of-bounds writes and memory safety issues. CVE-2026-58815, CVE-2026-55286, CVE-2026-55266, CVE-2026-49937, CVE-2026-49933, CVE-2026-49885, and CVE-2026-49880 all involve various forms of out-of-bounds writes or reads due to incorrect bounds checks, integer overflows, or resource exhaustion, leading to local privilege escalation. CVE-2026-55269, a High severity vulnerability, is a memory safety issue due to improper input validation in snoop_logger.cc, also leading to local privilege escalation. CVE-2026-49878, a High severity vulnerability, is an out-of-bounds write due to a logic error in robust_av.c, potentially leading to remote code execution. CVE-2026-28667, a Medium severity vulnerability, is an out-of-bounds read in rw_t5t.cc, leading to local information disclosure.
The disclosure of these 23 vulnerabilities on a single day highlights a significant security event for Android-x86 users. The prevalence of high-severity flaws, particularly those allowing for privilege escalation and code execution, underscores the critical need for prompt patching and security updates. Users are advised to consult the official Android-x86 project for any available patches or updated versions addressing these issues.
The batch includes vulnerabilities such as CVE-2026-58880, CVE-2026-58865, CVE-2026-58856, CVE-2026-58854, CVE-2026-58841, CVE-2026-58835, CVE-2026-58815, CVE-2026-55286, CVE-2026-55280, CVE-2026-55270, CVE-2026-55269, CVE-2026-55266, CVE-2026-55265, CVE-2026-49937, CVE-2026-49933, CVE-2026-49885, CVE-2026-49880, CVE-2026-49878, CVE-2026-45524, CVE-2026-28667, CVE-2026-28647, CVE-2026-28641, and CVE-2026-28640.