Executive brief
A vulnerability in the Android operating system's System component could allow a remote attacker to crash a device or cause a persistent service outage. This issue occurs automatically without requiring any user interaction or special account privileges. A successful exploit would disrupt the availability of the device, potentially requiring a reboot or causing ongoing operational issues.
Technical details
An integer overflow vulnerability exists within multiple functions of the ubsan_throwing_runtime.cpp file in the Android System component. The flaw allows for a remote denial of service (DoS) attack that does not require any additional execution privileges or user interaction. By exploiting this overflow, an attacker can cause a persistent crash or hang of the affected system services. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. Security patches were released in the June 2026 Android Security Bulletin to address this issue.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
- 2026-06-01: disclosed: NVD record published