Executive brief
The Android Framework contains improper data sanitization in multiple code locations due to logic errors. This vulnerability allows local information disclosure without requiring elevated privileges or user interaction. An attacker with access to the device could read sensitive data that should be protected.
Technical details
The vulnerability is an improper data sanitization flaw caused by a logic error in the Android Framework. It affects multiple locations within the codebase and enables local information disclosure without requiring additional execution privileges or user interaction. The attack vector is local, and no preconditions beyond basic device access are needed. Attackers can exploit this to read sensitive information. Patches are available in Android security patch level 2026-09-05 or later, with fixes released to AOSP for Android versions 14, 15, 16, 16-qpr2, and 17.
Affected products
- Google Android 14, 15, 16, 16-qpr2, 17
Timeline
- 2026-09-08: disclosed
- 2026-09-05: patched