---
id: CVE-2026-28653
title: >-
  In multiple functions of rw_t3t.cc, there is a possible out of bounds write
  due to an integer overflow
summary: >-
  In multiple functions of rw_t3t.cc, there is a possible out of bounds write
  due to an integer overflow. This could lead to local escalation of privilege
  with no additional execution privileges needed. User interaction is not needed
  for e…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
  - CWE-1190
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
  - android = 17.0
published: '2026-09-08'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:06:50.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-28653'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-09-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
epss: 0.00073
epssPercentile: 0.00082
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T16:19:31.104779Z'
ingestedAt: '2026-09-08T19:08:49.642Z'
---

## Overview

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`
- `android = 17.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
