Executive brief
A vulnerability in the Android operating system could allow a remote attacker to crash a device. This occurs due to a technical error in how the system handles certain mathematical calculations. An exploit could lead to a denial of service, temporarily disrupting device operations or causing a reboot without any action from the user.
Technical details
An integer overflow vulnerability exists within multiple functions of 'ubsan_throwing_runtime.cpp' in the Android System component. The flaw allows for a remote denial of service (DoS) attack. Exploitation does not require additional execution privileges or user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. A fix is available via the June 2026 Android Security Bulletin (patch level 2026-06-05).
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in Android Security Bulletin June 2026
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue