Vulnerabilities & Exploits

StrongBox Vulnerability Requires Multi-Vendor Coordination for Fixes

A high-severity vulnerability in Android's StrongBox hardware-backed keystore affects implementations from multiple Secure Element vendors including Google, NXP, STMicroelectronics, and Thales. This flaw complicates patching efforts because fixes must be coordinated across different hardware providers. The exact exploit impact remains undisclosed, but StrongBox weaknesses can lead to key extraction, privilege escalation, or denial-of-service. Additionally, a local denial-of-service vulnerability in the Android Framework (CVE-2026-0049) was patched, exploitable without special privileges or user interaction. Neither vulnerability shows signs of active exploitation yet. The multi-vendor nature of the StrongBox flaw signals ongoing challenges in securing hardware-backed key storage across diverse supply chains.

1 source · Apr 7

CVE-2026-0049

NVD KEV

CVSS 6.2 MEDIUM: in onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. EPSS 0.1% (1st percentile).

CVE-2025-48651

NVD KEV

Timeline

Sources

Part of the PlainSec briefing for 2026-04-08

Every edition of this story: StrongBox Vulnerability Requires Multi-Vendor Coordination for Fixes

More from today