PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28638 Google CVE debrief

A logic error in XmpDataParser.java could lead to local information disclosure with no additional execution privileges needed. This issue affects Android products using XmpDataParser.java. Defenders should assess exposure, verify data sanitization, and review affected versions for potential updates or patches. The CVE record and NVD entry provide details on the vulnerability. The logic error could allow unauthorized access to sensitive information. User interaction is not needed for exploitation.

Vendor
Google
Product
Android
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-15
Advisory published
2026-09-08
Advisory updated
2026-09-15

Who should care

Defenders of Android products using XmpDataParser.java should assess exposure and verify data sanitization. They should review affected versions for potential updates or patches. Security teams and vulnerability management teams should also review this issue. Operators of affected systems should verify data sanitization and assess exposure. This issue affects Android products using XmpDataParser.java.

Why it matters

CVE-2026-28638 is a logic error in XmpDataParser.java that could lead to local information disclosure. Defenders of Android products using this parser should assess exposure, verify data sanitization, and review affected versions for potential updates or patches.

  • Local information disclosure possible
  • Verify data sanitization in affected versions
  • Assess exposure in Android products

Technical summary

A logic error in XmpDataParser.java could lead to local information disclosure with no additional execution privileges needed. The issue affects Android products using XmpDataParser.java. The logic error could allow unauthorized access to sensitive information. Defenders should assess exposure, verify data sanitization, and review affected versions for potential updates or patches. The CVE record and NVD entry provide details on the vulnerability. User interaction is not needed for exploitation. This issue is a local information disclosure vulnerability.

Defensive priority

Assess exposure and verify data sanitization in Android products.

Recommended defensive actions

  • Assess exposure in Android products using XmpDataParser.java
  • Verify data sanitization in affected versions
  • Review and update affected Android versions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in XmpDataParser.java, which could lead to local information disclosure. The issue is caused by a logic error in the code. Defenders should verify data sanitization in affected versions and assess exposure in Android products. The CVE record was published on 2026-09-08T19:17:55.267Z and has not been modified since then. The NVD entry provides additional information on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28638 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28638

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28638 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28638

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.