CVE-2026-0056: Google Android
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected products
- Google Android: version 14.0 only; version 15.0 only; version 16.0 only
Published 2026-06-01. Last modified 2026-07-22.