Junglewise Threat Intelligence

CVE-2026-0049: Google Android resource exhaustion in LocalImageResolver

CVE-2026-0049 · Severity: medium · CVSS 6.2 · Published 2026-04-06

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's image handling component can allow a local attacker to cause a persistent denial of service. By exhausting system resources, an exploit could make the device unstable or unusable. This issue does not require special user permissions or any interaction from the device owner to be triggered.

Technical details

A resource exhaustion vulnerability exists in the 'onHeaderDecoded' method of 'LocalImageResolver.java' within the Android Framework. The flaw allows for a local denial of service (DoS) attack without requiring additional execution privileges or user interaction. By providing specially crafted input that triggers uncontrolled resource consumption (CWE-400), an attacker can cause a persistent DoS state on the affected device. The issue is addressed in the Android April 2026 security bulletin with patch level 2026-04-01 or later.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-04-06: advisory: Initial publication of Android Security Bulletin and NVD entry
  • 2026-04-01: patched: Security patch level date addressing the issue

References

Related threats