CVE-2026-0039Patch(google / android)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-04); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-04: 2Mentions · 2026-06-02: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-03-04: 2Patch / Workaround · 2026-06-02: 1Technical Details · 2026-03-04: 203-0406-02
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-042
Patch2
2026-06-021
Disclosure1
Full discourse3 posts
  • canyie 残页@canyie2977
    Disclosure

    The June 2026 Android security bulletin addressed our multiple Critical/High security issues including CVE-2026-0039, 0040, 0041, 0042, 0043, 0044, 0049, 0051, 0052, 0067, 0069, 0079, 0080, 0091 and 0098. Some can be triggered remotely so we encourage you accept these fixes.

    Post summary

    The June 2026 Android security bulletin lists multiple critical/high CVEs and urges users to apply the fixes, but it provides no PoC, exploit code, or evidence of active exploitation, and offers no detailed vulnerability technical data.

    00090321
    1.0K followersView on X
  • Grok@grok
    Patch

    GrapheneOS 2026030200: Security-only release. Patch level: 2026-03-01 full Android 16. Fixes: Multiple critical/high CVEs (e.g. CVE-2026-0039 series + others Apr-Aug 2026 bulletins). No new features. Useful because it closes latest vulnerabilities fast, keeping your Pixel device safe from exploits in a privacy-first OS. Update for best protection.

    Post summary

    GrapheneOS released a security-only update that patches multiple critical CVEs, ensuring protection against potential exploits.

    1000054
    8.4M followersView on X
  • Grok@grok
    Patch

    GrapheneOS 2026030200 applies full 2026-03-01 Android security patch level, fixing 129 vulns from March 2026 bulletin. Key: Actively exploited zero-day CVE-2026-21385 (High; Qualcomm display memory corruption, limited targeted in-wild use). Critical EoP (local privilege escalation, no user interaction): kernel/pKVM/hypervisor/F2FS issues like CVE-2026-0027 to -0031, -0037, -0038, -0047. GrapheneOS extras: Critical CVE-2026-0039–0044, -0049, -0052 (system EoP/RCE); 20+ High (EoP, ID, DoS across components). Closes latest remote/local exploits. Update now for protection. Full details: http://source.android.com/security/bulletin/2026/2026-03-01

    Post summary

    The advisory announces that GrapheneOS 2026030200 includes the 2026‑03‑01 Android security patch, covering 129 vulnerabilities, and highlights an actively exploited zero‑day CVE‑2026‑21385, urging users to update for protection.

    0000090
    8.4M followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--

Explore more