PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0049 Google CVE debrief

CVE-2026-0049 is a local denial of service vulnerability in LocalImageResolver.java due to resource exhaustion. No additional execution privileges are needed. This vulnerability affects Google Android 14.0, 15.0, 16.0, and 16.0 beta versions. Users of these versions should apply patches to prevent local denial of service attacks. The vulnerability is caused by resource exhaustion in LocalImageResolver.java, which can lead to a persistent denial of service. It is recommended that users of affected versions apply patches to prevent local denial of service attacks.

Vendor
Google
Product
Android
CVSS
MEDIUM 6.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of Google Android 14.0, 15.0, 16.0, and 16.0 beta versions should apply patches to prevent local denial of service attacks. Security teams and administrators responsible for managing Android devices should prioritize patching affected systems and review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. The vulnerability is due to resource exhaustion in LocalImageResolver.java, which can cause a persistent denial of service. Affected product deployments should be reviewed to confirm existence and assign an owner for follow-up.

Defensive priority

Medium priority due to CVSS score of 6.2 and potential for local denial of service attacks. It is recommended to confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Recommended defensive actions

  • Apply patches provided by Google for affected Android versions
  • Inventory and update vulnerable Android devices
  • Monitor for suspicious local activity
  • Implement compensating controls to limit resource exhaustion
  • Exception tracking for resource-intensive operations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record was published on 2026-04-06T19:16:26.280Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy. The source grounding indicates that the CVE record and NVD entry provide details on the vulnerability. However, additional verification is necessary to confirm the affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T19:16:26.280Z and has not been modified since then. The NVD entry is currently Analyzed.