Junglewise Threat Intelligence

CVE-2026-0052: Google Android integer overflow in ubsan_throwing_runtime.cpp

CVE-2026-0052 · Severity: info · CVSS 7.5 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system could allow a remote attacker to cause a device to crash or restart. This issue affects the core system components and does not require any user interaction or special permissions to exploit. Such an attack would primarily impact the availability of the device, potentially disrupting business operations or emergency communications.

Technical details

An integer overflow vulnerability exists within multiple functions of the 'ubsan_throwing_runtime.cpp' file in the Android System component. The flaw is triggered during the handling of specific runtime operations, leading to a memory corruption or logic error that results in a system crash. An attacker can exploit this remotely without any prior authentication or user interaction. The vulnerability is addressed in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later. Affected versions include Android 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Vulnerability disclosed in Android June 2026 Security Bulletin
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats