{"id":"ASB-A-484973621", "published":"2026-06-01T00:00:00Z", "modified":"2026-06-23T15:45:40.410020820Z", "aliases":["CVE-2026-0100", "A-484973621"], "details":"In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"17-next:0"}, {"fixed":"17-next:2026-06-01"}]}], "versions":["17-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"307169313865062868325471251248423105055", "length":10802}, "id":"ASB-A-484973621-35e873f6", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958", "target":{"file":"libs/androidfw/LoadedArsc.cpp", "function":"LoadedPackage::Load"}}, {"deprecated":false, "digest":{"line_hashes":["78350818810666849271249345144475063362", "61361269054877775450248921911125581146", "221851187440703759003140805735154998061", "200087880818464197053450652257171203066"], "threshold":0.9}, "id":"ASB-A-484973621-ec369263", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958", "target":{"file":"libs/androidfw/LoadedArsc.cpp"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"15:0"}, {"fixed":"15:2026-06-01"}]}], "versions":["15"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["78350818810666849271249345144475063362", "61361269054877775450248921911125581146", "221851187440703759003140805735154998061", "200087880818464197053450652257171203066"], "threshold":0.9}, "id":"ASB-A-484973621-40b87790", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368", "target":{"file":"libs/androidfw/LoadedArsc.cpp"}}, {"deprecated":false, "digest":{"function_hash":"104734282722271832316981151854006945191", "length":10243}, "id":"ASB-A-484973621-c1bf31d9", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368", "target":{"file":"libs/androidfw/LoadedArsc.cpp", "function":"LoadedPackage::Load"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16:0"}, {"fixed":"16:2026-06-01"}]}], "versions":["16"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"104734282722271832316981151854006945191", "length":10243}, "id":"ASB-A-484973621-9e10ca9b", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e", "target":{"file":"libs/androidfw/LoadedArsc.cpp", "function":"LoadedPackage::Load"}}, {"deprecated":false, "digest":{"line_hashes":["78350818810666849271249345144475063362", "61361269054877775450248921911125581146", "221851187440703759003140805735154998061", "200087880818464197053450652257171203066"], "threshold":0.9}, "id":"ASB-A-484973621-9f69521d", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e", "target":{"file":"libs/androidfw/LoadedArsc.cpp"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16-qpr2:0"}, {"fixed":"16-qpr2:2026-06-01"}]}], "versions":["16-qpr2"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["78350818810666849271249345144475063362", "61361269054877775450248921911125581146", "221851187440703759003140805735154998061", "200087880818464197053450652257171203066"], "threshold":0.9}, "id":"ASB-A-484973621-377ef0cc", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d", "target":{"file":"libs/androidfw/LoadedArsc.cpp"}}, {"deprecated":false, "digest":{"function_hash":"104734282722271832316981151854006945191", "length":10243}, "id":"ASB-A-484973621-8538f8f6", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d", "target":{"file":"libs/androidfw/LoadedArsc.cpp", "function":"LoadedPackage::Load"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14:0"}, {"fixed":"14:2026-06-01"}]}], "versions":["14"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"60998659444498194944723808679219033274", "length":10066}, "id":"ASB-A-484973621-16b59f6e", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807", "target":{"file":"libs/androidfw/LoadedArsc.cpp", "function":"LoadedPackage::Load"}}, {"deprecated":false, "digest":{"line_hashes":["78350818810666849271249345144475063362", "61361269054877775450248921911125581146", "221851187440703759003140805735154998061", "200087880818464197053450652257171203066"], "threshold":0.9}, "id":"ASB-A-484973621-76ddbd01", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807", "target":{"file":"libs/androidfw/LoadedArsc.cpp"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2026-06-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/frameworks/base/+/ca855338abcfd12831122437d9d01ede37539bd5"}]}