Executive brief
A security vulnerability exists in the Android Framework, the core set of software components that provide essential services to mobile apps. An attacker could exploit this flaw to gain elevated system privileges on a device without needing any special permissions or user interaction. This could allow a malicious app to bypass security restrictions and access sensitive data or perform unauthorized actions.
Technical details
A vulnerability in the Google Android Framework component (specifically tracked as A-481967442) is caused by an incorrect bounds check across multiple functions. This flaw leads to a 'desync in persistence,' which can be leveraged by a local attacker to achieve escalation of privilege (EoP). The exploit requires no additional execution privileges and no user interaction. The issue affects Android versions 16 and 16-qpr2. Security patch levels of 2026-06-05 or later address this vulnerability.
Affected products
- Google Android Framework 16, 16-qpr2
Timeline
- 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
- 2026-06-01: disclosed