Executive brief
A vulnerability in the Android operating system could allow a local attacker to cause a persistent denial of service. This issue affects the system's runtime error handling components and could lead to device instability or crashes without requiring any user interaction or special permissions. Successful exploitation would disrupt the normal operation of the device and its applications.
Technical details
An integer overflow vulnerability exists within multiple functions of ubsan_throwing_runtime.cpp in the Android System component. The flaw is triggered during runtime error handling, where improper integer arithmetic can lead to a persistent denial of service (DoS) condition. An attacker can exploit this locally without needing additional execution privileges or user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. Patches have been released as part of the June 2026 Android Security Bulletin.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed in Android June 2026 Security Bulletin
- 2026-06-01: advisory: NVD record published