CVE-2026-58865: Google Android vulnerability
Published Oct 5, 2026
·Updated
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 5, 2026
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionWeakness
Frequently Asked Questions
1
Does an attacker need local access, execution privileges, or user interaction to exploit this issue?
No. The issue is described as remotely exploitable, requires no additional execution privileges, and does not require user interaction.
2
What should responders prioritize when assessing affected Android deployments?
Assess exposure to the affected PduParser.java functions, because the missing bounds check can cause persistent denial of service. The provided information does not identify affected Android versions or available mitigations.