Executive brief
A vulnerability in the Android Framework could allow a malicious application installed on a device to gain elevated system privileges. This issue occurs within the component responsible for handling system resources and does not require any special permissions or user interaction to exploit. If successful, an attacker could gain unauthorized access to sensitive data or perform actions with higher authority than normally permitted.
Technical details
An out-of-bounds read vulnerability exists in the 'validateNode' function within 'ResourceTypes.cpp' of the Android Framework. The flaw is caused by an incorrect bounds check when processing resource nodes. A local attacker can exploit this vulnerability to achieve escalation of privilege (EoP) without needing any specific execution privileges or user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. A fix is available as part of the June 2026 Android Security Bulletin (patch level 2026-06-05).
Affected products
- Google Android Framework 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in Android Security Bulletin June 2026
- 2026-06-01: disclosed: CVE published to NVD dataset