CVE-2026-28633: Security vulnerability
Published Sep 8, 2026
·Updated
In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs local access only; no additional execution privileges are required. Exploitation does not require user interaction.
2
What is the expected impact if exploitation succeeds?
The issue can cause persistent denial of service through resource exhaustion.