Description
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the graphics driver update routine of Android can cause a persistent denial of service. The bug arises during the execution of the updateState method in GraphicsDriverEnableAngleAsSystemDriverController.java, and it can maintain the device in a non‑responsive state. The issue does not require elevated privileges or user interaction, meaning that any local user could trigger the denial of service simply by exercising the graphics subsystem, potentially rendering the device unusable until reboot or device wipe.

Affected Systems

This flaw affects Google Android devices. No specific product version or build information is provided, so the flaw could be present in any Android release that includes the affected graphics driver code. Administrators should treat all current Android devices as potentially vulnerable until the vendor releases a patch or update that addresses the flaw.

Risk and Exploitability

The CVSS score of 5.5 and an unavailable EPSS score indicate that public exploitation data is not yet known. The flaw is listed as not being part of the CISA KEV catalog. Because local access is sufficient and no special execution privileges are required, the risk is primarily to device availability rather than confidentiality or integrity. Exploitability relies on a local user triggering a graphics operation that enters the vulnerable state, so mitigating the impact hinges on applying the vendor’s fix or rebooting the device if it becomes unresponsive.

Generated by OpenCVE AI on June 2, 2026 at 03:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android update that contains the graphics driver fix once it becomes available.
  • If a patch is not yet released, mitigate by rebooting the device promptly when it becomes unresponsive and avoid running graphics‑heavy applications until an update is applied.
  • Stay informed through Google’s security bulletin page and apply any interim advisories or workarounds provided by the vendor.

Generated by OpenCVE AI on June 2, 2026 at 03:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
Title Persistent Local Denial of Service via Graphics Driver Update in Android
Weaknesses CWE-739

Tue, 02 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service in Android Graphics Driver Update State
Weaknesses CWE-703
CWE-770

Tue, 02 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service in Android Graphics Driver Update State
Weaknesses CWE-703
CWE-770

Mon, 01 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T23:46:02.515Z

Reserved: 2025-10-15T15:40:38.124Z

Link: CVE-2026-0060

cve-icon Vulnrichment

Updated: 2026-06-01T23:45:58.840Z

cve-icon NVD

Status : Received

Published: 2026-06-01T22:16:21.063

Modified: 2026-06-02T00:16:35.120

Link: CVE-2026-0060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T03:30:26Z

Weaknesses