Executive brief
A vulnerability exists in the Android operating system that could allow a remote attacker to crash a device. This is caused by a technical error in how the system handles certain numbers, leading to a denial of service. An exploit could disrupt operations or cause device instability without requiring any user interaction or special permissions.
Technical details
An integer overflow vulnerability exists within multiple functions of the 'ubsan_throwing_runtime.cpp' component in the Android System. The flaw is triggered when the runtime handles specific arithmetic operations, leading to a memory corruption or logic error that results in a system crash. This vulnerability is reachable remotely and does not require any execution privileges or user interaction (Zero-Click). Successful exploitation allows an attacker to cause a permanent or temporary Denial of Service (DoS) on affected devices. The issue is addressed in the June 2026 Android Security Bulletin with patch levels 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in Android Security Bulletin and NVD
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue