CVE-2026-0006Disclosure(google / android)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-10); latest day: 2
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
android

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 2Mentions · 2026-03-26: 1Mentions · 2026-04-02: 1Mentions · 2026-05-07: 2PoC Mentioned / Linked · 2026-05-07: 1Exploit Tool / Code · 2026-05-07: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-04-02: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-26: 1Technical Details · 2026-05-07: 103-0303-0503-0603-1003-2604-0205-07
Signal classification5 categories
Disclosure
222.2%
General
222.2%
Active Exploitation
222.2%
Patch
222.2%
PoC
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-031
Disclosure1
2026-03-051
General1
2026-03-061
General1
2026-03-102
Active Exploitation1Patch1
2026-03-261
Disclosure1
2026-04-021
Active Exploitation1
2026-05-072
Patch1PoC1
Full discourse9 posts
  • rooten@r00teen
    Patch

    1/7 HP Android kamu bisa dibajak tanpa kamu klik apapun. Bukan clickbait. Ini CVE-2026-0006 vulnerability yang baru dipatch Google Maret 2026. CVSS score-nya 9.8 / CRITICAL, masuk kategori heap buffer overflow yang bisa berujung ke Remote Code Execution. Kalau HP kamu belum diupdate, lanjut baca. 🧵

    Post summary

    The tweet announces that Google has patched CVE-2026-0006, a critical heap buffer overflow RCE vulnerability, in March 2026, but offers no PoC, exploit code, or evidence of active exploitation.

    2002178
    1.2K followersView on X
  • rooten@r00teen
    PoC

    5/7 Sudah ada PoC publik? Ada 2 public PoC/exploit yang sudah tersedia di GitHub, termasuk exploit MP4 dan standalone ARM64 PoC. Ini berarti barrier eksploitasi makin rendah bukan cuma theoretical lagi. 🔗 CVE Detail: http://cvefeed.io/vuln/detail/CVE-2026-0006

    Post summary

    The post confirms that public PoC/exploit code for CVE‑2026‑0006 is available on GitHub, reducing the exploitation barrier; no evidence of active attacks, patches, or technical details is provided.

    1000016
    472 followersView on X
  • Alt43@BurpWeb
    Disclosure

    2/5 🔓 Otra de las más graves es la CVE-2026-0006: permite ejecución remota de código sin que el usuario haga nada ni se necesiten permisos adicionales. Es decir, un atacante podría comprometer el dispositivo sin interacción alguna.

    Post summary

    El tweet anuncia la CVE-2026-0006, describiendo que permite ejecución remota de código sin interacción del usuario ni permisos adicionales.

    1000028
    82 followersView on X
  • Grok@grok
    Active Exploitation

    Latest as of Mar 2026: - CVE-2025-48593 (Nov 2025 bulletin): Critical zero-click RCE in Android System/Bluetooth component (A13-16). No user interaction or privileges needed; patched at security level 2025-11-01. - Project Zero Pixel 9 0-click chain (disclosed Oct 2025): Dolby UDC audio decoder (CVE-2025-54957) + kernel driver; patched on Pixel Jan 2026. - Mar 2026 bulletin: CVE-2026-0006 critical RCE in Media Codecs (no user interaction needed). Actively exploited zero-day CVE-2026-21385 is Qualcomm graphics (local, not zero-click). Update ASAP to latest patch level.

    Post summary

    The bulletin lists several critical Android RCEs, several of which have already been patched, and highlights an actively exploited Qualcomm graphics CVE that requires immediate remediation.

    01000124
    8.4M followersView on X
  • BountyLife@BountyLif3
    General

    The scariest part? CVE-2026-0006. We’re looking at Zero-Click RCE in the System component. No user interaction. No "Allow" prompt. Just code execution. This isn't just a patch- it's an emergency evacuation for your old firmware.

    Post summary

    The text announces CVE‑2026‑0006 as a zero‑click remote code execution in a system component that executes code without user interaction, emphasizing the need for urgent firmware updates.

    1000050
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0006 - Critical In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges need... https://www.thehackerwire.com/vulnerability/CVE-2026-0006/ https://t.co/sCLAtgMOgW

    Post summary

    The post announces CVE-2026-0006, detailing a heap buffer overflow that could enable remote code execution, but it does not provide a PoC, exploit, or patch information.

    0000178
    121 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    NoVoice malware infiltrated 50+ Android apps on Google Play, reaching 2.3M downloads before exploitation. Attackers rooted devices via CVE-2026-0006, then injected code across all running apps to access cross-application data including WhatsApp sessions. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/novoice-android-malware-google-play-2026 #MobileSecurity #ThreatIntel

    Post summary

    NoVoice malware exploited CVE‑2026‑0006 to root Android devices and inject malicious code into multiple apps, demonstrating active exploitation of the vulnerability.

    0000077
    1.9K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    Android's March 2026 security patch fixes 100+ flaws, including critical RCE in Media Codecs (CVE-2026-0006) and multiple pKVM kernel EoP bugs. Patch ASAP if you're on Android 14–16. https://www.helpnetsecurity.com/2026/03/03/android-march-2026-security-patch-cve-2026-21385/

    Post summary

    Android’s March 2026 patch updates fix more than a hundred flaws, including a critical RCE (CVE‑2026‑0006) and several kernel EoP bugs, and users are urged to apply the patch immediately.

    0000052
    151 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Android ❗ CVE-2026-0047 ❗ CVE-2026-0037 ❗ CVE-2026-0006 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-android-3/ https://t.co/Iaewb4K5Qd

    Post summary

    The tweet announces three Android product CVEs with links for additional details but provides no further technical or exploitation information.

    00000122
    6.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid16.0--

Explore more