GoogleCVE-2026-55256
Google Android: denial of service
Medium6.5CVE-2026-55256 · Published Sep 8, 2026 · updated Sep 24, 2026
In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= 17 | No fix yet |
| <= 16-qpr2 | No fix yet | |
| <= 16 | No fix yet | |
| <= 15 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-20
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Google Android Wear: information disclosure | Critical10.0 | No fix yet |
| Sep 8 | Google Android XR: privilege escalation | Critical10.0 | No fix yet |
| Sep 8 | Google Android: use after free | High7.8 | No fix yet |
| Sep 8 | Google Android: race condition | High7.0 | No fix yet |
| Sep 8 | Google Android: privilege escalation | High7.8 | No fix yet |
| Sep 8 | Google Android: out-of-bounds read | High7.8 | No fix yet |