Executive brief
A vulnerability in the Android operating system could allow a local attacker to cause a persistent denial of service. This occurs through resource exhaustion, which can make the device unresponsive or unusable. The issue does not require special user privileges or interaction to exploit, potentially impacting device availability and operational continuity.
Technical details
A vulnerability classified as Uncontrolled Resource Consumption (CWE-400) exists in multiple locations within the Android Framework. The flaw allows for a persistent denial of service (DoS) via resource exhaustion. An attacker can exploit this locally without needing additional execution privileges or user interaction. While the CNA provided a CVSS 4.0 score of 10.0 (Critical) with a network attack vector, the technical description and Android's own classification categorize it as a local DoS with 'High' severity. The issue is addressed in Android 17 with a security patch level of 2026-07-01 or later.
Affected products
- Google Android 17
Timeline
- 2026-06-16: advisory: Android 17 Security Release Notes published
- 2026-06-17: disclosed: NVD publication date