In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:* |
Tue, 02 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:* |
Tue, 02 Jun 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Information Disclosure via Bounds Check Failure in ResourceTypes.cpp |
Tue, 02 Jun 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Read out of bounds causing local information disclosure in Android ResourceTypes | |
| Weaknesses | CWE-119 CWE-200 |
Tue, 02 Jun 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Read out of bounds causing local information disclosure in Android ResourceTypes | |
| Weaknesses | CWE-119 CWE-200 |
Mon, 01 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-06-01T21:14:52.922Z
Updated: 2026-06-01T23:26:16.237Z
Reserved: 2025-10-15T15:40:31.342Z
Link: CVE-2026-0056
Updated: 2026-06-01T23:26:07.893Z
Status : Analyzed
Published: 2026-06-01T22:16:20.883
Modified: 2026-06-03T13:47:11.550
Link: CVE-2026-0056
No data.