Executive brief
A vulnerability in the Android Framework could allow a malicious application installed on a device to access sensitive information it should not be able to see. This occurs due to a technical error in how the system handles certain resource files. An attacker could exploit this without any special permissions or user interaction, potentially compromising user privacy.
Technical details
An out-of-bounds read vulnerability exists in the 'setTo' function within 'ResourceTypes.cpp' of the Android Framework. The flaw is caused by an incorrect bounds check when processing resources. A local attacker can exploit this to read memory contents, leading to information disclosure. No additional execution privileges or user interaction are required for exploitation. The issue is addressed in the June 2026 Android Security Bulletin for Android versions 14, 15, 16, and 16-qpr2.
Affected products
- Google Android Framework 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.