Executive brief
A security vulnerability has been identified in Google Android Wear OS, the operating system used for smartwatches and wearable devices. An attacker could exploit this flaw to cause a persistent denial of service, effectively making the device unusable or preventing critical system functions from operating. This attack can be carried out by a malicious application already on the device without requiring any special permissions or user interaction.
Technical details
A denial of service (DoS) vulnerability exists in the Framework component of Android Wear OS due to a missing permission check within the AndroidManifest.xml file. A local attacker can exploit this vulnerability without needing additional execution privileges or user interaction. The flaw allows for a persistent denial of service state on the affected device. The issue is addressed in the June 2026 Android Security Bulletin with security patch level 2026-06-01 or later. Affected versions include Android Wear OS 14 and 16.
Affected products
- Google Android Wear OS 14, 16
Timeline
- 2026-06-01: patched: Security patch level 2026-06-01 released to address the issue.
- 2026-06-18: disclosed: NVD published the CVE details.