Junglewise Threat Intelligence

CVE-2026-0039: Google Android integer overflow in ubsan_throwing_runtime.cpp

CVE-2026-0039 · Severity: info · CVSS 7.5 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's System component could allow a remote attacker to crash a device or cause a persistent service outage. This issue occurs automatically without requiring any user interaction or special account privileges. A successful exploit would disrupt the availability of the device, potentially requiring a reboot or causing ongoing operational issues.

Technical details

An integer overflow vulnerability exists within multiple functions of the ubsan_throwing_runtime.cpp file in the Android System component. The flaw allows for a remote denial of service (DoS) attack that does not require any additional execution privileges or user interaction. By exploiting this overflow, an attacker can cause a persistent crash or hang of the affected system services. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. Security patches were released in the June 2026 Android Security Bulletin to address this issue.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: disclosed: NVD record published

References

Related threats