CVE-2026-0059: Buffer Overflow
Published Jun 1, 2026
·Updated
In multiple functions of sdpdiscovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Jun 1, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0059?
CVE-2026-0059 has a high severity rating of 8 according to the CVSS scoring system.
2
What type of vulnerability is CVE-2026-0059?
CVE-2026-0059 is classified as a buffer overflow vulnerability.
3
How can I fix CVE-2026-0059?
To fix CVE-2026-0059, ensure that your Google Android device is updated with the latest security patches provided by Google.
4
What are the potential impacts of CVE-2026-0059?
CVE-2026-0059 may allow for remote code execution without requiring any user interaction, leading to severe security implications.
5
Which software is affected by CVE-2026-0059?
CVE-2026-0059 affects Google Android software.