Junglewise Threat Intelligence

CVE-2026-0051: Google Android denial of service in ubsan_throwing_runtime.cpp

CVE-2026-0051 · Severity: info · CVSS 9.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's System component could allow a remote attacker to crash a device. This issue affects the core stability of the phone or tablet, potentially leading to a denial of service where the device becomes unresponsive or reboots unexpectedly. No user interaction or special permissions are required for an attacker to trigger this crash.

Technical details

A denial of service (DoS) vulnerability exists in the Android System component, specifically within multiple functions of 'ubsan_throwing_runtime.cpp'. The root cause is improper input validation, which can be triggered to cause a system crash. The attack vector is remote and requires no additional execution privileges or user interaction. This vulnerability is rated as Critical by Google and affects Android versions 14, 15, 16, and 16-qpr2. Security patch levels of 2026-06-05 or later address this issue.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability disclosed in June 2026 Android Security Bulletin.
  • 2026-06-01: advisory: NVD record published.

References

Related threats