Junglewise Threat Intelligence

CVE-2026-0069: Google Android Framework resource exhaustion in ApkChecksums

CVE-2026-0069 · Severity: info · CVSS 5.5 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's application verification process can allow a malicious local application to crash the system. By exhausting system resources during a signature check, an attacker can cause a denial of service, making the device or specific features unavailable. This issue does not require any special user interaction or elevated permissions to trigger.

Technical details

A resource exhaustion vulnerability exists in the 'verifySignature' method of 'ApkChecksums.java' within the Android Framework. The flaw allows a local attacker to trigger a system crash by providing crafted input that consumes excessive system resources during the APK checksum verification process. This results in a local Denial of Service (DoS). The attack requires no additional execution privileges and no user interaction. The vulnerability is addressed in the June 2026 Android Security Bulletin for Android version 14.

Affected products

  • Google Android Framework 14

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: disclosed: CVE-2026-0069 published to NVD

References

Related threats