Junglewise Threat Intelligence

CVE-2026-28573: Google Android Wear OS denial of service in Framework

CVE-2026-28573 · Severity: medium · CVSS 5.5 · Published 2026-06-18

Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Android Wear OS, the operating system used for smartwatches and wearable devices. An attacker could exploit this flaw to cause a persistent denial of service, effectively making the device unusable or preventing critical system functions from operating. This attack can be carried out by a malicious application already on the device without requiring any special permissions or user interaction.

Technical details

A denial of service (DoS) vulnerability exists in the Framework component of Android Wear OS due to a missing permission check within the AndroidManifest.xml file. A local attacker can exploit this vulnerability without needing additional execution privileges or user interaction. The flaw allows for a persistent denial of service state on the affected device. The issue is addressed in the June 2026 Android Security Bulletin with security patch level 2026-06-01 or later. Affected versions include Android Wear OS 14 and 16.

Affected products

  • Google Android Wear OS 14, 16

Timeline

  • 2026-06-01: patched: Security patch level 2026-06-01 released to address the issue.
  • 2026-06-18: disclosed: NVD published the CVE details.

References