CVE-2026-58865 Overview
CVE-2026-58865 is a persistent denial-of-service vulnerability in the Android PduParser.java component. The flaw stems from a missing bounds check across multiple functions that parse Protocol Data Units (PDUs), typically used for Multimedia Messaging Service (MMS) handling. A remote attacker can trigger the condition without user interaction and without any privileges on the target device. Google documented the issue in the October 2026 Android Security Bulletin and classified it under [CWE-119] (Improper Restriction of Operations within the Bounds of a Memory Buffer). The vulnerability affects Android versions 14, 15, 16, and 17.
Critical Impact
Remote attackers can cause a persistent denial of service on affected Android devices without user interaction or elevated privileges.
Affected Products
- Google Android 14.0
- Google Android 15.0 and 16.0 (including QPR2 Beta 1-3)
- Google Android 17.0
Discovery Timeline
- 2026-10-01 - Google publishes the Android Security Bulletin addressing the issue
- 2026-10-05 - CVE-2026-58865 published to the National Vulnerability Database (NVD)
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-58865
Vulnerability Analysis
The vulnerability resides in PduParser.java, a class responsible for parsing Protocol Data Units used by Android's messaging stack. Multiple parsing functions fail to validate the size or offset of attacker-controlled fields before performing read or write operations. When the parser processes a malformed PDU, the missing bounds check leads to abnormal termination of the handling process. Because the messaging subsystem repeatedly attempts to parse the same message, the condition becomes persistent and effectively renders the affected functionality unusable until the malicious message is removed.
Root Cause
The root cause is improper restriction of operations within the bounds of a memory buffer [CWE-119]. The affected parsing routines in PduParser.java operate on length fields and offsets supplied inside the PDU without verifying them against the actual buffer size. Attacker-crafted length values therefore drive the parser to access memory outside intended limits, producing an unrecoverable exception every time the message is reprocessed.
Attack Vector
Exploitation occurs over the network. An attacker sends a crafted PDU, such as a malformed MMS message, to the target device. The messaging subsystem automatically invokes the vulnerable parser during message handling, so no user interaction is required. Successful exploitation does not disclose data or grant code execution; the impact is limited to availability of the messaging service and potentially related system components that invoke the parser. The persistent nature of the denial of service distinguishes it from transient parsing errors.
See the Android Security Bulletin October 2026 for component-level technical details.
Detection Methods for CVE-2026-58865
Indicators of Compromise
- Repeated crashes or restarts of the messaging process (com.android.mms or carrier messaging apps) in device logs.
- Inbound MMS or WAP push messages from unknown senders immediately preceding service degradation.
- logcat entries showing exceptions originating from PduParser stack frames.
Detection Strategies
- Monitor mobile device management (MDM) telemetry for Android devices that report unpatched security patch levels prior to the October 2026 bulletin.
- Correlate carrier-side MMS gateway logs with device crash reports to identify malformed PDU delivery patterns.
- Alert on repeated restart cycles of messaging-related processes across managed Android fleets.
Monitoring Recommendations
- Track the Android security patch level reported by enrolled devices and flag any device below the 2026-10-01 patch level.
- Review carrier or enterprise MMS logs for high volumes of malformed or oversized PDUs targeting specific subscribers.
- Integrate Android device logs with your security data lake to detect anomalous messaging-service terminations at scale.
How to Mitigate CVE-2026-58865
Immediate Actions Required
- Apply the October 2026 Android security patch level (2026-10-01 or later) to all affected devices through OEM update channels.
- Prioritize patching for devices used by high-risk users whose phone numbers are publicly exposed.
- Remove any suspect MMS messages from affected devices to clear the persistent crash condition.
Patch Information
Google addressed CVE-2026-58865 in the Android Security Bulletin October 2026. The fix adds the missing bounds checks to the affected functions in PduParser.java. Device OEMs incorporate the patch into their own monthly updates; confirm availability with the device vendor and carrier.
Workarounds
- Disable automatic retrieval of MMS messages in the default messaging application to prevent unattended parsing of untrusted PDUs.
- Restrict inbound MMS at the carrier or enterprise gateway where feasible until devices receive the patch.
- Advise users to avoid opening MMS messages from unknown senders on unpatched devices.
# Verify the Android security patch level on a connected device
adb shell getprop ro.build.version.security_patch
# Expected output for patched devices: 2026-10-01 or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.