CVE-2026-28667 Overview
CVE-2026-28667 is an out-of-bounds read vulnerability in multiple functions within the rw_t5t.cc source file of the Android Near Field Communication (NFC) stack. The flaw results from a missing bounds check when processing Type 5 Tag (T5T) data. A local attacker with low privileges can trigger the condition to disclose process memory contents without any user interaction. The issue affects Android versions 14, 15, 16, and 17 and is tracked under CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer.
Critical Impact
Local information disclosure of adjacent memory contents from the Android NFC process, with no additional execution privileges or user interaction required.
Affected Products
- Google Android 14.0
- Google Android 15.0
- Google Android 16.0 (including QPR2)
- Google Android 17.0
Discovery Timeline
- 2026-10-05 - CVE-2026-28667 published to the National Vulnerability Database
- 2026-10-01 - Addressed in the Android Security Bulletin October 2026
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-28667
Vulnerability Analysis
The vulnerability resides in rw_t5t.cc, the Reader/Writer implementation for NFC Forum Type 5 Tags (ISO/IEC 15693-based tags) in the Android NFC stack. Multiple functions in this file read tag response data without validating that buffer offsets and length fields remain within the allocated receive buffer. When a crafted T5T response is parsed, the code reads past the end of the buffer and returns adjacent heap memory to the caller.
The attacker needs local access with low privileges, typically a malicious application on the device or a locally reachable NFC code path. The read-only nature of the flaw means integrity and availability are not directly affected, but leaked memory may contain pointers, tokens, or other process state usable to defeat Address Space Layout Randomization (ASLR) or stage further attacks.
Root Cause
The root cause is a missing bounds check prior to indexed buffer access. Functions in rw_t5t.cc trust length and offset values derived from parsed tag payloads instead of validating them against the actual size of the receive buffer. This is a classic [CWE-119] boundary violation in C++ parsing code that handles attacker-influenced inputs.
Attack Vector
Exploitation requires local access with low privileges on the Android device. An attacker leverages the NFC stack's T5T parsing path to supply or influence a malformed tag response. The parser then reads out-of-bounds and surfaces the leaked bytes through NFC APIs or logs. No user interaction is required for the parsing to occur.
Verified public exploitation code is not available at the time of publication, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Refer to the Android Security Bulletin October 2026 for the authoritative fix description.
Detection Methods for CVE-2026-28667
Indicators of Compromise
- Unexpected crashes or memory-related errors logged by the com.android.nfc process in logcat.
- Installation of applications that request android.permission.NFC without a clear functional need.
- Anomalous NFC tag read activity initiated by background applications on devices running Android 14 through 17.
Detection Strategies
- Compare installed Android build fingerprints against the October 2026 Android Security Bulletin patch level to identify unpatched fleet devices.
- Monitor mobile endpoint telemetry for repeated NFC service faults or restarts, which can indicate attempted exploitation of the T5T parser.
- Review application behavior for processes that interact with NFC APIs outside normal user-triggered workflows.
Monitoring Recommendations
- Ingest Android device security patch level and build data into a central inventory to track exposure to CVE-2026-28667.
- Alert on sideloaded or newly installed applications that acquire NFC permissions on managed devices.
- Correlate NFC subsystem errors with application install and launch events across your mobile fleet.
How to Mitigate CVE-2026-28667
Immediate Actions Required
- Apply the October 2026 Android security patch level (2026-10-01 or later) to all affected Android 14, 15, 16, and 17 devices.
- Enforce the patched baseline through mobile device management (MDM) compliance policies and block non-compliant devices from sensitive resources.
- Restrict installation of applications requesting NFC permissions to vetted sources.
Patch Information
Google addressed CVE-2026-28667 in the Android Security Bulletin October 2026. Device manufacturers ship the fix as part of the 2026-10-01 security patch level. Pixel devices receive the update directly from Google, while other original equipment manufacturers (OEMs) distribute the patch on their own schedules.
Workarounds
- Disable NFC in system settings on devices that cannot immediately receive the October 2026 patch.
- Limit physical and local access to affected devices to reduce the opportunity for a local attacker to trigger the parser.
- Remove or restrict applications that are not required to use NFC functionality.
# Verify the Android security patch level on a connected device
adb shell getprop ro.build.version.security_patch
# Expected output for patched devices: 2026-10-01 or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.