Executive brief
A vulnerability exists in the Android operating system's runtime error checking component. An attacker could exploit this to cause a persistent denial of service, effectively making the device or specific system functions unusable. This attack can be carried out locally on the device without requiring any special permissions or user interaction.
Technical details
A resource exhaustion vulnerability exists within multiple functions of ubsan_throwing_runtime.cpp in the Android System component. The flaw allows for a persistent denial of service (DoS) through the exhaustion of system resources. The attack vector is local, requiring no additional execution privileges and no user interaction. This issue affects Android versions 14, 15, 16, and 16-qpr2. Google has addressed this vulnerability in the June 2026 Android Security Bulletin with security patch level 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.