Executive brief
A logic error in the Android System component can allow a local attacker to cause a permanent denial of service. This affects the Undefined Behavior Sanitizer (UBSan) runtime, which is used to detect and handle code errors. An exploit could result in a device becoming unresponsive or requiring a factory reset, impacting user operations and device availability.
Technical details
A logic error exists within multiple functions of ubsan_throwing_runtime.cpp in the Android System component. This vulnerability is classified as a Denial of Service (DoS) and can be triggered by a local attacker without any special privileges or user interaction. The flaw resides in the Undefined Behavior Sanitizer (UBSan) throwing runtime, where improper logic handling can lead to a permanent system hang or crash. Google has addressed this in the June 2026 Android Security Bulletin. Patches are available for Android versions 14, 15, 16, and 16-qpr2.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Published in the June 2026 Android Security Bulletin
- 2026-06-01: advisory: NVD record published