Executive brief
Android's System component contains a flaw in how it validates input to the parsePartHeaders function across multiple files. An attacker can trigger a persistent denial of service by sending specially crafted network requests, causing the Android device to become unresponsive without requiring any special permissions or user interaction. This could disrupt device availability and user operations.
Technical details
The vulnerability exists in the parsePartHeaders function across multiple files in Android's System component and stems from improper input validation. The flaw can be exploited remotely over the network without requiring elevated privileges, user interaction, or authentication. An attacker can craft malicious input to trigger a persistent denial of service condition, causing resource exhaustion or infinite loops that render the device unresponsive. The vulnerability affects Android versions prior to the 2026-09-05 security patch level; patches have been released to AOSP and are available in updated versions (Android 14, 15, 16, 16-qpr2, and 17).
Affected products
- Google Android Prior to 2026-09-05 security patch level (affects Android 14, 15, 16, 16-qpr2, 17)
Timeline
- 2026-09-08: disclosed: Android Security Bulletin published September 8, 2026
- 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this vulnerability