Junglewise Threat Intelligence

CVE-2026-0100: Google Android Framework heap buffer overflow in LoadedArsc.cpp

CVE-2026-0100 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android Framework could allow a malicious application to gain elevated system privileges without any user interaction. This component is responsible for managing core system resources and application interactions. If exploited, an attacker could bypass security restrictions to access sensitive data or perform unauthorized actions on the device.

Technical details

A heap buffer overflow exists in the 'Load' function within 'LoadedArsc.cpp' of the Android Framework. The vulnerability is caused by an out-of-bounds write when processing resource files. A local attacker can exploit this flaw to achieve escalation of privilege (EoP) to a higher-level system context. The attack requires no special execution privileges and no user interaction. Google has addressed this in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later.

Affected products

  • Google Android Framework 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats