Junglewise Threat Intelligence

CVE-2026-55290: Android ResourceTypes.cpp out-of-bounds heap read

CVE-2026-55290 · Severity: low · CVSS 3.3 · Published 2026-09-08

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in Android's resource handling code allows reading beyond allocated memory boundaries due to missing input validation. An attacker with local access can exploit this to leak sensitive information from device memory, including cryptographic keys or user data, without needing special permissions or user interaction.

Technical details

The vulnerability exists in the setTo() function of ResourceTypes.cpp in the Android System component. A missing bounds check allows an out-of-bounds heap read when processing malformed resource data. The vulnerability requires local access to trigger and can lead to information disclosure. No additional execution privileges are required. The Android Security Bulletin indicates patches are available in AOSP versions 14, 15, 16, 16-qpr2, and 17 as of the 2026-09-05 security patch level.

Affected products

  • Google Android 14, 15, 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed: Published in Android Security Bulletin
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue

References

Related threats