Android-x86: Thirteen Vulnerabilities Disclosed, Ranging from Critical to Medium Severity
Key findings • Thirteen vulnerabilities disclosed for Android-x86 on September 15, 2026. • Includes Critical and High severity flaws impacting privilege escalation and remote code execution. …

Key findings
- Thirteen vulnerabilities disclosed for Android-x86 on September 15, 2026.
- Includes Critical and High severity flaws impacting privilege escalation and remote code execution.
- Vulnerabilities affect components like SMMU, VP9 decoding, and IP Multimedia Subsystem.
- Several flaws involve memory corruption, race conditions, and improper bounds checking.
- Exploitation requires no user interaction, increasing the risk for affected systems.
On September 15, 2026, a batch of thirteen vulnerabilities was disclosed for Android-x86, a popular open-source operating system designed to run Android applications on PCs. The vulnerabilities, all disclosed on the same day, span a range of severity levels, including critical and high-impact flaws, and primarily concern privilege escalation and remote code execution. These issues could allow attackers to gain unauthorized access and control over affected systems without user interaction.
Several vulnerabilities stem from memory corruption and improper bounds checking within various components of the Android-x86 system. CVE-2026-58751, CVE-2026-58747, and CVE-2026-58739, all rated Medium, involve use-after-free logic errors, permission bypasses due to confused deputy vulnerabilities, and logic errors in platform message handling, respectively. These could lead to local privilege escalation.
Higher severity flaws include CVE-2026-58728 (High), a race condition in ARM64_TLBI leading to memory corruption, and CVE-2026-58699 (High), an out-of-bounds read in the Vp9DecEndOfStream component due to an incorrect bounds check. Most critically, CVE-2026-56942 (High), CVE-2026-55331 (High), and CVE-2026-0170 (High) all involve out-of-bounds writes in video decoding components (VP9) or the IP Multimedia Subsystem, potentially leading to remote code execution or privilege escalation. The most severe vulnerability, CVE-2026-55331, is a Critical flaw in the IP Multimedia Subsystem, allowing for remote code execution via an authentication bypass.
Other notable vulnerabilities include CVE-2026-58698 and CVE-2026-56922, both Medium severity, stemming from confused deputy vulnerabilities leading to permission bypasses. CVE-2026-56915 (Medium) is a race condition in bigo.c that could lead to privilege escalation, while CVE-2026-0183 (Medium) involves a confused deputy in CPM leading to information disclosure.
The disclosed vulnerabilities affect multiple components, including the SMMU driver, message handlers, ARM MMU, video processing units (VP9), IP Multimedia Subsystem, and power management IC (PMIC) handlers. The common theme across many of these CVEs is the potential for local privilege escalation, with several also posing a risk of remote code execution.
As of the disclosure date, no specific information regarding patches or vendor advisories has been released. Users of Android-x86 are advised to monitor the official Android-x86 project for any security updates or patches related to these vulnerabilities. Given the severity of some of these flaws, particularly those allowing for remote code execution, prompt patching will be crucial for mitigating potential exploitation. The lack of user interaction required for exploitation in many of these CVEs increases their risk profile, making proactive security measures essential.
This batch of vulnerabilities underscores the importance of ongoing security audits and timely patching for operating system components, especially those that handle complex media processing or network communications. Users should remain vigilant for any official communications from the Android-x86 project regarding remediation efforts.
The vulnerabilities disclosed are: CVE-2026-58751, CVE-2026-58747, CVE-2026-58739, CVE-2026-58728, CVE-2026-58699, CVE-2026-58698, CVE-2026-56942, CVE-2026-56922, CVE-2026-56915, CVE-2026-55331, CVE-2026-55331, CVE-2026-0183, and CVE-2026-0170. It is important to note that CVE-2026-55331 was listed twice in the input data. The final list of unique CVEs is: CVE-2026-58751, CVE-2026-58747, CVE-2026-58739, CVE-2026-58728, CVE-2026-58699, CVE-2026-58698, CVE-2026-56942, CVE-2026-56922, CVE-2026-56915, CVE-2026-55331, CVE-2026-0183, CVE-2026-0170.