CVE-2026-0006
CRITICALGoogle Android - Heap Buffer Overflow
Title source: llmDescription
In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploits (2)
github
STUB
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-0006
nomisec
1 stars
by mobilehackinglab · poc
https://github.com/mobilehackinglab/CVE-2026-0006-openapv-poc
Scores
CVSS v3
9.8
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-122
Status
published
Products (1)
google/android
16.0
Published
Mar 02, 2026
Tracked Since
Mar 03, 2026