PatchSiren cyber security CVE debrief
CVE-2026-0049 Google CVE debrief
CVE-2026-0049 is a local denial of service vulnerability in LocalImageResolver.java due to resource exhaustion. No additional execution privileges are needed. This vulnerability affects Google Android 14.0, 15.0, 16.0, and 16.0 beta versions. Users of these versions should apply patches to prevent local denial of service attacks. The vulnerability is caused by resource exhaustion in LocalImageResolver.java, which can lead to a persistent denial of service. It is recommended that users of affected versions apply patches to prevent local denial of service attacks.
- Vendor
- Product
- Android
- CVSS
- MEDIUM 6.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Users of Google Android 14.0, 15.0, 16.0, and 16.0 beta versions should apply patches to prevent local denial of service attacks. Security teams and administrators responsible for managing Android devices should prioritize patching affected systems and review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. The vulnerability is due to resource exhaustion in LocalImageResolver.java, which can cause a persistent denial of service. Affected product deployments should be reviewed to confirm existence and assign an owner for follow-up.
Defensive priority
Medium priority due to CVSS score of 6.2 and potential for local denial of service attacks. It is recommended to confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Recommended defensive actions
- Apply patches provided by Google for affected Android versions
- Inventory and update vulnerable Android devices
- Monitor for suspicious local activity
- Implement compensating controls to limit resource exhaustion
- Exception tracking for resource-intensive operations
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-04-06T19:16:26.280Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy. The source grounding indicates that the CVE record and NVD entry provide details on the vulnerability. However, additional verification is necessary to confirm the affected scope and severity.
Official resources
-
CVE-2026-0049 CVE record
CVE.org
-
CVE-2026-0049 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T19:16:26.280Z and has not been modified since then. The NVD entry is currently Analyzed.