Android Runtime Undefined Behavior Sanitizer Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in the Android Runtime's Undefined Behavior Sanitizer (UBSan) component. This issue arises from multiple functions in 'ubsan_throwing_runtime.cpp', where improper handling of resources can lead to exhaustion, causing a persistent denial-of-service condition. The vulnerability can be exploited locally without requiring additional execution privileges or user interaction.
Impact
Exploitation of this vulnerability leads to resource exhaustion, causing a local denial-of-service condition.
Remediation
Users can update their devices to the June 2026 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
