CVE-2026-28596

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-08 19:17

Updated : 2026-09-15 14:25


NVD link : CVE-2026-28596

Mitre link : CVE-2026-28596

CVE.ORG link : CVE-2026-28596


JSON object : View

Products Affected

google

  • android
CWE
CWE-400

Uncontrolled Resource Consumption