Impact
The vulnerability resides in the parsePartHeaders function across multiple files in the Android operating system. The function performs insufficient input validation, allowing an attacker to supply crafted input that can cause the system to enter a persistent denial‑of‑service state. The attack does not require any elevated execution privileges and can be carried out remotely without any user interaction. If successfully exploited, an attacker can render the device unusable by causing the relevant processes to hang or consume excessive resources.
Affected Systems
All devices running the Android operating system are potentially affected, as the flaw exists in core system components that are deployed across many Android releases. The specific affected versions are not listed in the CVE data, but the issue is addressed in the 2026‑09‑01 security bulletin, implying earlier versions prior to that update may be vulnerable.
Risk and Exploitability
The EPSS score is < 1% (approximately 0.00158), indicating a very low but non-zero likelihood of exploitation. The CVSS score of 6.5 categorizes this flaw as medium severity. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, involving the delivery of malicious files or attachments that trigger the parsePartHeaders routine. Because the flaw causes a persistent service disruption rather than code execution, the primary risk is availability loss for the device.
OpenCVE Enrichment