Skip to main content
Vulnerability Database/CVE-2026-55265

CVE-2026-55265: Google Android DOS Vulnerability

CVE-2026-55265 is a denial of service vulnerability in Google Android that allows remote attackers to crash devices through out of bounds reads. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-55265 Overview

CVE-2026-55265 is an out-of-bounds read vulnerability in multiple functions of PduParser.java in Google Android. The flaw stems from a missing bounds check during Protocol Data Unit (PDU) parsing operations. An attacker can trigger a remote denial of service without user interaction. The vulnerability does not grant additional execution privileges, limiting impact to availability.

The issue is tracked under CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer and affects Android versions 14.0 through 17.0. Google addressed the issue in the Android Security Bulletin - October 2026.

Critical Impact

Remote attackers can crash the messaging subsystem by sending a crafted PDU, disrupting SMS and MMS availability on affected devices without any user action.

Affected Products

  • Google Android 14.0
  • Google Android 15.0
  • Google Android 16.0 (including QPR2)
  • Google Android 17.0

Discovery Timeline

  • 2026-10-05 - CVE-2026-55265 published to the National Vulnerability Database (NVD)
  • 2026-10-01 - Patch released in the Android Security Bulletin
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-55265

Vulnerability Analysis

The vulnerability resides in PduParser.java, a Java class responsible for parsing Protocol Data Units used in Multimedia Messaging Service (MMS) transport. Multiple parsing functions dereference buffer offsets without validating that the requested index remains within the allocated byte array. When a malformed PDU is processed, the parser reads memory outside the intended bounds.

The out-of-bounds read raises an unchecked exception inside the messaging stack. The exception propagates through the parsing chain and terminates the handling process. Because the affected code path can be reached via network-delivered messages, exploitation requires no user interaction. Confidentiality and integrity are not impacted; the sole outcome is denial of service against the messaging component.

Root Cause

The root cause is a missing bounds check in several PDU parsing routines. Length and offset fields taken from attacker-controlled input are used directly to index into parsing buffers. The code lacks validation ensuring the computed read position stays within the buffer length, which maps to [CWE-119].

Attack Vector

Exploitation occurs over the network. An attacker sends a specially crafted PDU, such as a malformed MMS or WAP push message, to a target device. The Android messaging subsystem parses the PDU automatically on receipt. The malformed structure triggers the out-of-bounds read and causes the handling process to crash, requiring process restart to resume normal messaging.

No verified proof-of-concept code is publicly available. See the Android Security Bulletin - October 2026 for vendor-provided technical details.

Detection Methods for CVE-2026-55265

Indicators of Compromise

  • Repeated crashes or restarts of the Android messaging process (com.android.mms or com.google.android.apps.messaging) in device logs.
  • Unexpected ArrayIndexOutOfBoundsException entries referencing PduParser stack frames in logcat output.
  • Inbound MMS or WAP push traffic from unknown senders coinciding with messaging service failures.

Detection Strategies

  • Monitor Android crash reports and ANR traces for exceptions originating in PduParser.java.
  • Correlate carrier-level MMS gateway logs for anomalous PDU structures or malformed message delivery attempts.
  • Baseline normal messaging process uptime per device and alert on repeated termination events.

Monitoring Recommendations

  • Centralize mobile device telemetry, including crash logs and process restarts, into a SIEM for anomaly analysis.
  • Track Android security patch level (ro.build.version.security_patch) across the fleet to identify unpatched endpoints.
  • Alert on devices still reporting a pre-October 2026 patch level after the enterprise rollout window closes.

How to Mitigate CVE-2026-55265

Immediate Actions Required

  • Apply the October 2026 Android security patch to all affected devices as soon as the OEM release is available.
  • Inventory the fleet to identify devices running Android 14.0, 15.0, 16.0, 16.0 QPR2, or 17.0 without the current patch level.
  • Prioritize patching for high-risk users and devices exposed to untrusted messaging senders.

Patch Information

Google published the fix in the Android Security Bulletin - October 2026. Devices must report a security patch level of 2026-10-01 or later to be considered remediated. OEM and carrier distribution timelines vary; coordinate with device vendors for availability on managed hardware.

Workarounds

  • Disable automatic retrieval of MMS messages in the default messaging application until patches are installed.
  • Restrict messaging from unknown senders through carrier-level filtering where available.
  • Use mobile device management (MDM) policies to enforce patch compliance and quarantine non-compliant devices from sensitive resources.
bash
# Check Android security patch level via ADB
adb shell getprop ro.build.version.security_patch

# Expected output for remediated devices:
# 2026-10-01 (or later)

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.