Junglewise Threat Intelligence

CVE-2026-0080: Google Android integer overflow in ubsan_throwing_runtime.cpp

CVE-2026-0080 · Severity: info · CVSS 7.5 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability exists in the Android operating system that could allow a remote attacker to cause a device to crash or restart. This issue affects the core system components and can be triggered without any user interaction or special permissions. Such an attack results in a denial of service, potentially disrupting communications or business operations on affected mobile devices.

Technical details

An integer overflow vulnerability exists within multiple functions of the 'ubsan_throwing_runtime.cpp' file in the Android System component. The flaw is reachable over the network and does not require any specific execution privileges or user interaction to trigger. Successful exploitation allows an attacker to cause a crash of the affected process, leading to a remote denial of service (DoS) condition. The issue is addressed in the June 2026 Android Security Bulletin with security patch levels 2026-06-05 or later.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats