GoogleCVE-2026-28596
Google Android: denial of service
Medium5.5CVE-2026-28596 · Published Sep 8, 2026 · updated Sep 15, 2026
In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= 16-qpr2 | No fix yet |
| <= 16 | No fix yet | |
| <= 15 | No fix yet | |
| <= 14 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-400
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Google Android Wear: information disclosure | Critical10.0 | No fix yet |
| Sep 8 | Google Android XR: privilege escalation | Critical10.0 | No fix yet |
| Sep 8 | Google Android: use after free | High7.8 | No fix yet |
| Sep 8 | Google Android: race condition | High7.0 | No fix yet |
| Sep 8 | Google Android: privilege escalation | High7.8 | No fix yet |
| Sep 8 | Google Android: out-of-bounds read | High7.8 | No fix yet |