Description
In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

The vulnerability resides in Android’s VoiceInteractionManagerService, where inadequate handling of resource allocation can lead to persistent exhaustion. Attackers can trigger a local denial of service without requiring any elevated privileges. Because the flaw does not need user interaction, any local user or malicious application can exploit it. The weakness aligns with CWE-770 (Allocation of Resources Without Limits). The primary impact is disruption of the voice interaction subsystem, potentially rendering the device unusable until restarted.

Affected Systems

The affected vendor is Google, specifically the Android operating system. At present, no specific Android version range is listed in the advisory. Administrators should verify whether their current device builds include the VoiceInteractionManagerService components referenced in the description.

Risk and Exploitability

The CVSS score is 5.5, and the EPSS score is <1%, indicating a low probability of exploitation. However, the vulnerability requires only local access and no special privileges, meaning any local user can exploit it. While the issue is not yet listed in CISA KEV, the ability to cause a persistent denial of service creates a moderate to high risk to device availability. The likely attack vector is local, with a straightforward trigger that consumes system resources until a reboot or service restart occurs.

Generated by OpenCVE AI on September 11, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Android to the latest release once Google issues an official fix.
  • If the device is not engaged in voice interaction tasks, disable or remove any unused voice interaction service packages to reduce the attack surface.
  • Monitor system logs and resource usage for abnormal activity related to VoiceInteractionManagerService, and perform a reboot or restart of the service upon detection of excessive resource consumption.

Generated by OpenCVE AI on September 11, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*

Tue, 15 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service via Android Voice Interaction Manager

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Persistent Resource Exhaustion Denial of Service in Android VoiceInteractionManagerService
Weaknesses CWE-730

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Persistent Resource Exhaustion Denial of Service in Android VoiceInteractionManagerService
Weaknesses CWE-730
CWE-770

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T16:26:09.428Z

Reserved: 2026-03-02T19:11:13.943Z

Link: CVE-2026-28633

cve-icon Vulnrichment

Updated: 2026-09-10T16:23:30.573Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:54.987

Modified: 2026-09-15T14:03:11.307

Link: CVE-2026-28633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling