Executive brief
A vulnerability exists in the Android operating system's System component that could allow a malicious application to gain higher-level system privileges. This issue is caused by a technical error in how the system handles certain mathematical calculations, potentially leading to a persistent service outage or unauthorized access. An attacker could exploit this without any interaction from the device user.
Technical details
An integer overflow vulnerability exists within multiple functions of 'ubsan_throwing_runtime.cpp' in the Android System component. The flaw allows a local attacker to trigger a persistent denial of service (DoS) or achieve local escalation of privilege (EoP). Exploitation does not require additional execution privileges or user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2, and is addressed in the June 2026 security patch level (2026-06-05).
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in Android Security Bulletin June 2026
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue