Android
- >= 14, < 14.0.0
- ~15
- ~16
- ~16-qpr2
A critical elevation of privilege vulnerability has been identified in the Android Framework and System components. This issue arises from an integer overflow in multiple functions of 'ubsan_throwing_runtime.cpp', leading to a possible persistent denial of service. Exploitation of this vulnerability could allow local escalation of privilege without requiring additional execution privileges or user interaction. Affected devices can be updated to the June 2026 security patch level to address this vulnerability.
Exploitation of this vulnerability could lead to unauthorized access to elevated privileges, allowing a user to perform actions or access resources that are normally restricted.
To address this vulnerability, users should update their devices to the June 2026 security patch level. Instructions for checking and updating the security patch level are available on the Android Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.