Junglewise Threat Intelligence

CVE-2026-0085: Google Android improper input validation in DataRowHandler.java

CVE-2026-0085 · Severity: info · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's contact handling component could allow a malicious application to crash the system or cause it to become unresponsive. By providing an excessively long contact name that bypasses normal size limits, an attacker can trigger a denial-of-service condition. This issue can be exploited without any special permissions or user interaction, potentially disrupting the device's availability and normal operations.

Technical details

An improper input validation vulnerability exists in the 'applySimpleFieldMaxSize' method within 'DataRowHandler.java' of the Android Framework. The flaw allows for the insertion of a contact name that exceeds expected size constraints. A local attacker can exploit this to trigger a denial-of-service (DoS) condition on the affected device. Exploitation does not require elevated privileges or user interaction. The issue is addressed in the June 2026 Android Security Bulletin for AOSP versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-05: patched: Security patch levels of 2026-06-05 or later address this issue.

References

Related threats