Out-of-Bounds Heap Read in ResourceTypes.cpp for Android Devices
CVE-2026-55290

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-55290?

An out-of-bounds heap read vulnerability exists in the ResourceTypes.cpp file in Android, where a missing bounds check could allow for local information disclosure. This vulnerability can be exploited without requiring additional execution privileges or user interaction, posing a significant risk to the confidentiality of sensitive data on affected Android devices. System administrators and users should be aware of this issue to protect their data from potential exploitation.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.