Out of Bounds Read in Android's PduParser.java Affects Android Devices
CVE-2026-55265

6.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-55265?

In the PduParser.java file of the Android operating system, multiple functions exhibit a potential out of bounds read vulnerability due to inadequate bounds checking. This can be exploited remotely, allowing an attacker to cause a denial of service without requiring any extra execution privileges. There is no need for user interaction to exploit this vulnerability, which poses a significant risk to the affected Android devices.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.