CVE-2026-0049Disclosure(google / android)

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 5 mentions (2026-04-07); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline13 mentions / 7d
01345Mentions · 2026-04-07: 5Mentions · 2026-04-08: 3Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-07: 3Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-07: 4Technical Details · 2026-04-08: 2Technical Details · 2026-04-11: 104-0704-0804-0904-1004-1104-1604-17
Signal classification3 categories
Disclosure
538.5%
Patch
538.5%
General
323.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-075
Disclosure3Patch2
2026-04-083
Disclosure1General1Patch1
2026-04-091
Patch1
2026-04-101
Patch1
2026-04-111
Disclosure1
2026-04-161
General1
2026-04-171
General1
Full discourse13 posts
  • XiaomiTime@timexiaomi
    Patch

    Xiaomi HyperOS April 2026 patch fixes critical zero-click DoS. - CVE-2026-0049: Android Framework DoS mitigated - StrongBox hardware security fix patched - Google Play System Updates unchanged this month - Patch levels: 04-01 for core, 04-05 for ful… https://ift.tt/SAIs4Fp

    Post summary

    The tweet announces that Xiaomi's HyperOS April 2026 patch addresses CVE-2026-0049 by mitigating a critical zero-click DoS in the Android Framework, with explicit patch levels provided.

    110150947
    12.2K followersView on X
  • ねこすず(ナナチ・チョコミント)@nanachi_mint
    Patch

    Androidを使っているかた大事なセキュリティ確認を! Android OSに「CVE-2026-0049」という深刻な不具合が見つかりましたが、最新のアップデートで修正が始まっています。 自分のスマホが安全な状態かどうか、以下の手順で確認してみてください。

    Post summary

    The post announces a critical Android OS vulnerability (CVE‑2026‑0049) and informs users that a fix is already being applied through the latest update, urging them to verify their device's security.

    10021165
    300 followersView on X
  • Chevalyetek@chevalyetek
    Disclosure

    Google konfime yon vilnerabilite kritik CVE-2026-0049 ki afekte Android 14, 15 ak 16. Li ka eksplwate san aksyon itilizatè a epi fè telefòn nan pa fonksyone. Mete dènye mizajou sekirite Android la Kounya. #Chevalyetek https://t.co/HmyQAq2bad

    Post summary

    Google confirms a critical CVE-2026-0049 affecting Android 14‑16 that can be exploited without user interaction, urging users to install the latest security update.

    0102081
    3 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 51% of vulnerabilities from past week, CVE-2026-0049 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post reports that CVE-2026-0049 has the most articles that week and provides a link for more information, but supplies no technical or operational details.

    0000057
    69 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 41% of vulnerabilities from past week, CVE-2026-0049 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The statement notes that CVE-2026-0049 has many articles but provides no details on exploitation, patches, or technical aspects.

    0000036
    69 followersView on X
  • しーにゃ♪@公式@Syynya
    Patch

    Google、2026年4月のAndroid セキュリティ公開情報を公表、危険な脆弱性(CVE-2026-0049)を修正 https://rocket-boys.co.jp/security-measures-lab/android-april-2026-security-update-cve-2026-0049/ 4/6 に公表された件。

    Post summary

    Google announced the April 2026 Android security update, noting that CVE-2026-0049 has been fixed. A link to the advisory is provided.

    0000058
    924 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、2026年4月のAndroid セキュリティ公開情報を公表、危険な脆弱性(CVE-2026-0049)を修正 https://rocket-boys.co.jp/security-measures-lab/android-april-2026-security-update-cve-2026-0049/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google announced the April 2026 Android security update that includes a fix for CVE‑2026‑0049.

    00000132
    373 followersView on X
  • CyberWolfGuard@CyberWolfGuard
    Disclosure

    🚨 Android Security Alert: Google discloses CVE-2026-0049: a zero interaction DoS flaw in Android 14–16. No user action needed to exploit, devices can be rendered unresponsive. Patch now via April 2026 update (2026-04-05+). #Android #CyberSecurity https://t.co/V96zhwmiWV

    Post summary

    Google has publicly disclosed CVE-2026-0049, a zero-interaction DoS vulnerability in Android 14–16, with a patch available in the upcoming April 2026 update.

    0000061
    10 followersView on X
  • 金井康訓@kanaiyasunori
    General

    https://source.android.com/docs/security/bulletin/2026/2026-04-01?hl=ja CVE-2026-0049 重大なセキュリティ問題があったから、対応されたのかも。

    Post summary

    The snippet notes that CVE-2026-0049 was identified as a serious security issue, but no additional technical or mitigation details are provided.

    0000069
    53 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Android Zero-Interaction DoS and StrongBox High-Severity Vulnerabilities (CVE-2026-0049, CVE-2025-48651) 📅 **Timeline:** Disclosure: 2026-04-06; Patches: 2026-04-01 & 2026-04-05 🆔 **CVE-2026-0049** | 📊 CVSS: 6.2 (MEDIUM 🟡) | 📈 EPSS: 0.303% 🆔 **CVE-2025-48651** | 📊 CVSS: (HIGH 🟠) | 📈 EPSS: 0.772% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Android 14, Android 15, Android 16/16-qpr2, StrongBox implementations (pre-2026-04-05) 🔧 **Fixed Versions:** Security patch level 2026-04-01, Security patch level 2026-04-05 🫨 **Attack Vectors:** - Local — zero-interaction local DoS (CVE-2026-0049); no user interaction required - Hardware/StrongBox implementation issue — local/firmware impact (CVE-2025-48651) 📝 **Summary:** CVE-2026-0049 allows a zero-interaction local DoS that can crash or reboot Android devices, while CVE-2025-48651 is a high-severity flaw in StrongBox implementations that may risk hardware-backed key storage. Both affect wide ranges of Android 14/15/16 devices and StrongBox-enabled hardware worldwide — apply vendor patches immediately. 📈 **Impact Scope:** Widespread Android devices worldwide (Android 14/15/16/16-qpr2) and StrongBox-enabled devices across multiple vendors; impact includes local denial-of-service and potential compromise of hardware-backed key storage components. 🛡️ **Recommended Actions:** - Apply Android security updates immediately and ensure devices are at security patch level 2026-04-05 or later - Prioritize patching Android 14/15/16 (incl. 16-qpr2) and StrongBox devices; verify via Settings > Security > Security patch level - Monitor device stability/logs for crashes or reboots and restrict unnecessary local access until patched - Coordinate with OEMs/vendors for vendor-specific firmware and StrongBox fixes 🪢 **Related Resources:** - https://source.android.com/docs/security/bulletin/2026/2026-04-01 - https://nvd.nist.gov/vuln/detail/CVE-2025-48651 🏷 **Tags:** #Cybersecurity #Android #StrongBox

    Post summary

    The alert announces CVE-2026-0049 and CVE-2025‑48651, detailing technical metrics and impacted Android/StrongBox devices, and urges immediate application of the 2026‑04‑01/04‑05 security patches.

    00000130
    276 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Android StrongBox Hardware Keystore Vulnerabilities (CVE-2025-48651, CVE-2026-0049) 📅 **Timeline:** Disclosure: 2026-04-01, Patch: 2026-04-01 🆔 **CVE-2025-48651** | 📊 CVSS: (High 🟠) | 📈 EPSS: 0.772% 🆔 **CVE-2026-0049** | 📊 CVSS: 6.2 (MEDIUM 🟡) | 📈 EPSS: 0.303% 🛠️ **Exploit Maturity:** Not Available (no known public exploit) 📂 **Affected Versions:** StrongBox implementations (Google, NXP, STMicroelectronics, Thales), Android Framework (LocalImageResolver) — Android < 2026-04-05 🔧 **Fixed Versions:** Android security update (2026-04-01), Security patch level 2026-04-05 or later 🫨 **Attack Vectors:** - Potential key extraction, privilege escalation, or keystore denial-of-service via StrongBox (technical details not published) - Local resource exhaustion causing persistent denial-of-service in LocalImageResolver (no privileges/user interaction required) 📝 **Summary:** The April 2026 Android bulletin patches a High-severity StrongBox keystore flaw (CVE-2025-48651) that could enable cryptographic key extraction, privilege escalation or keystore DoS, and a Medium Framework flaw (CVE-2026-0049) enabling local persistent DoS via LocalImageResolver. Devices using affected StrongBox SE implementations or Android builds before the April 2026 patch should be considered at risk. 📈 **Impact Scope:** Potential cryptographic key compromise, local privilege escalation, and DoS impacting device availability; affects devices with impacted StrongBox SEs and Android builds before the April 2026 patch. 🛡️ **Recommended Actions:** - Apply the Android security update (April 2026 / security bulletin 2026-04-01) immediately - Verify and apply vendor/SoC StrongBox firmware updates for Google, NXP, STMicroelectronics, and Thales 🪢 **Related Resources:** - https://www.securityweek.com/severe-strongbox-vulnerability-patched-in-android/ - https://source.android.com/docs/security/bulletin/2026/2026-04-01 🏷 **Tags:** #Cybersecurity #Android #StrongBox

    Post summary

    Android issued a security bulletin fixing two high‑severity StrongBox keystore flaws, one leading to potential key extraction and privilege escalation and the other causing a local DoS. Apply the April 2026 update and vendor firmware patches immediately.

    00000129
    276 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-0049 - Apache HTTP Server Resource Exhaustion Denial of Service Vulnerability Intel Report: https://ift.tt/g2Mfe8F

    Post summary

    A new Apache HTTP Server CVE (CVE-2026-0049) is highlighted as a resource exhaustion DoS vulnerability; no PoC, exploit, or patch details are provided.

    0000071
    281 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0049 Persistent Denial of Service via Resource Exhaustion in LocalImage... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0049 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑0049 as a persistent DoS vulnerability due to resource exhaustion, linking to a vulnerability detail page but providing no PoC, exploit, or patch information.

    0000065
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--

Explore more