Junglewise Threat Intelligence

CVE-2026-0067: Google Android System denial of service in ubsan_throwing_runtime.cpp

CVE-2026-0067 · Severity: info · CVSS 6.2 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android System component can allow a local attacker to cause a permanent denial of service. This affects the Undefined Behavior Sanitizer (UBSan) runtime, which is used to detect and handle code errors. An exploit could result in a device becoming unresponsive or requiring a factory reset, impacting user operations and device availability.

Technical details

A logic error exists within multiple functions of ubsan_throwing_runtime.cpp in the Android System component. This vulnerability is classified as a Denial of Service (DoS) and can be triggered by a local attacker without any special privileges or user interaction. The flaw resides in the Undefined Behavior Sanitizer (UBSan) throwing runtime, where improper logic handling can lead to a permanent system hang or crash. Google has addressed this in the June 2026 Android Security Bulletin. Patches are available for Android versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: advisory: NVD record published

References

Related threats