Executive brief
A vulnerability in the Android operating system's accessibility services could allow a malicious application to cause a persistent crash or system instability. This issue affects the core component responsible for managing accessibility features for users with disabilities. If exploited, it could lead to a permanent denial of service on the device, requiring technical intervention to restore normal operation.
Technical details
A denial of service vulnerability exists in the Android Framework within the AccessibilityManagerService.java component. The flaw is caused by improper input validation across multiple functions within the service. A local attacker can exploit this without any special execution privileges or user interaction to trigger a persistent denial of service state. The vulnerability is addressed in the June 2026 Android Security Bulletin for AOSP versions 15, 16, and 16-qpr2. While the NVD entry lists the severity as 'info', the primary vendor (Android) has classified this as 'High' severity.
Affected products
- Google Android Framework 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-01: patched