Description
In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the GameManagerService of Android, the parseInterventionFromXml function can consume excessive resources, causing the device to crash permanently. The flaw does not require administrative privileges, nor user interaction; an attacker could simply trigger the vulnerable XML parsing path to bring the system down. The primary impact is a local denial of service, rendering the device unusable until restarted or patched.

Affected Systems

Android devices running the GameManagerService component are impacted, specifically editions of the operating system distributed by Google that include the referenced GameManagerService module. No specific Android version is listed, so any device with this component is potentially vulnerable until it receives the security fix.

Risk and Exploitability

The vulnerability is exploitable locally without any special privileges, making it straightforward for an attacker with physical or local access to cause service interruption. The CVSS score of 5.5 indicates medium severity. The EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation, and the vulnerability is not currently listed in CISA's KEV catalog. Nevertheless, the risk remains significant given the ease of exploitation and the severity of the denial of service it can trigger.

Generated by OpenCVE AI on September 11, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that addresses the GameManagerService XML parsing issue.
  • Reduce or restrict the use of applications that interact with GameManagerService to limit until a fix is deployed.
  • If the service is not essential, disable the GameManagerService component to prevent exploitation.

Generated by OpenCVE AI on September 11, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title GameManagerService XML Resource Exhaustion Denial of Service

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Android GameManagerService Denial of Service via XML Parsing Resource Exhaustion
Weaknesses CWE-754

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Android GameManagerService Denial of Service via XML Parsing Resource Exhaustion
Weaknesses CWE-754

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T17:14:40.603Z

Reserved: 2026-03-02T19:11:02.946Z

Link: CVE-2026-28596

cve-icon Vulnrichment

Updated: 2026-09-10T17:14:37.724Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:52.240

Modified: 2026-09-15T14:25:40.567

Link: CVE-2026-28596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T22:00:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption