Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a crafted WebM file with a big-endian PCM audio track.
android poc cve android-security matroska security-research asan webmcp libwebm cve-2026-28609 libstagefright mediaframework
-
Updated
Sep 21, 2026 - Shell