CVE-2026-0049
CVSS 6.2 MEDIUM: in onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. EPSS 0.1% (1st percentile).
Vulnerabilities · 161 days ago
A high-severity vulnerability in Android's StrongBox hardware-backed keystore affects implementations from multiple Secure Element vendors including Google, NXP, STMicroelectronics, and Thales. This flaw complicates patching efforts because fixes must be coordinated across different hardware providers. The exact exploit impact remains undisclosed, but StrongBox weaknesses can lead to key extraction, privilege escalation, or denial-of-service. Additionally, a local denial-of-service vulnerability in the Android Framework (CVE-2026-0049) was patched, exploitable without special privileges or user interaction. Neither vulnerability shows signs of active exploitation yet. The multi-vendor nature of the StrongBox flaw signals ongoing challenges in securing hardware-backed key storage across diverse supply chains.
CVSS 6.2 MEDIUM: in onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. EPSS 0.1% (1st percentile).
1 source covering this story
Severe StrongBox Vulnerability Patched in Android
A critical DoS vulnerability in the Framework component of Android has also been fixed with the latest update.
Part of the PlainSec briefing for 2026-04-08