CVE-2026-0044: Integer Overflow
Published Jun 1, 2026
·Updated
In multiple functions of ubsanthrowingruntime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
7 affected components
llvm UndefinedBehaviorSanitizer (UBSan) runtime
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Jun 1, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0044?
The severity of CVE-2026-0044 is medium with a CVSS score of 6.5.
2
How do I fix CVE-2026-0044?
To fix CVE-2026-0044, ensure that your software is updated to the latest security patch provided by Google.
3
What does CVE-2026-0044 affect?
CVE-2026-0044 affects the Google Android and llvm UndefinedBehaviorSanitizer (UBSan) runtime (LLVM).
4
What type of vulnerability is CVE-2026-0044?
CVE-2026-0044 is classified as an integer overflow vulnerability.
5
Can CVE-2026-0044 be exploited without user interaction?
Yes, CVE-2026-0044 can be exploited remotely without user interaction.