{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-0049",
        "assignerOrgId": "baff130e-b8d5-4e15-b3d3-c3cf5d5545c6",
        "state": "PUBLISHED",
        "assignerShortName": "google_android",
        "dateReserved": "2025-10-15T15:39:42.902Z",
        "datePublished": "2026-04-06T18:20:38.337Z",
        "dateUpdated": "2026-05-27T16:51:02.351Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "baff130e-b8d5-4e15-b3d3-c3cf5d5545c6",
                "shortName": "google_android",
                "dateUpdated": "2026-04-13T16:57:00.317Z"
            },
            "datePublic": "2026-04-05T18:30:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "description": "Denial of service"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Google",
                    "product": "Android",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "16-qpr2"
                        },
                        {
                            "status": "affected",
                            "version": "16"
                        },
                        {
                            "status": "affected",
                            "version": "15"
                        },
                        {
                            "status": "affected",
                            "version": "14"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://source.android.com/docs/security/bulletin/2026/2026-04-01",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Cxxsheng (曹圣) and Yanjie Zhao (赵彦杰) of Huazhong University of Science and Technology (华中科技大学) and Canyie(石松洲) of LSPosed Team.",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "cvelib 1.7.1"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-400",
                                "lang": "en",
                                "description": "CWE-400 Uncontrolled Resource Consumption"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 6.2,
                            "attackVector": "LOCAL",
                            "baseSeverity": "MEDIUM",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                            "integrityImpact": "NONE",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "NONE",
                            "confidentialityImpact": "NONE"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-04-06T18:39:39.296981Z",
                                "id": "CVE-2026-0049",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-05-27T16:51:02.351Z"
                }
            }
        ]
    }
}