CVE-2026-0049

Published Apr 6, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-0049 is a critical vulnerability identified within the Android Framework component. This flaw can lead to a local denial-of-service (DoS) condition on affected devices. The vulnerability is particularly notable because its exploitation requires no user interaction, making it a "zero-click" exploit, and no additional execution privileges are needed for an attacker to trigger the DoS. This issue impacts several recent Android versions, including Android 14, 15, 16, and 16-qpr2.

Description
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Analyzed
Products
android

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.2
Impact score
3.6
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.