ZeroHour

CVE-2026-55256

mass

Remote Persistent Denial-of-Service in Android parsePartHeaders (CVE-2026-55256)

CVSS 3.1
6.5 medium
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-55256 is an improper input validation flaw in the parsePartHeaders routine of Android, which parses message part headers; malformed content processed by this parser can trigger a persistent denial of service. It can be triggered remotely, with no attacker privileges and no user interaction required, by delivering crafted data to the affected parsing code. An attacker gains a sustained, persistent denial-of-service condition on the affected device or component; no code execution, privilege escalation, or data exposure is described. Any Android build containing the vulnerable parsing code is affected, but the available data does not specify which Android versions or ranges are impacted. There is currently no known exploitation, no public proof of concept, a low predicted exploitation probability (EPSS 0.2%, 5th percentile), and the flaw is not in the CISA KEV catalog.

What to do: Apply Android security updates from Google or your device OEM as soon as they reach your devices, including the September 2026 security update cycle, and confirm the installed security patch level in device settings afterward. No workaround is specified in the available data; prioritize devices that ingest remote content automatically (e.g., email or messaging services), since exploitation needs no user interaction or privileges. Monitor the Android security bulletin and OEM advisories for the concrete patched versions once published.

Affected
Google (Android / AOSP; CNA: [email protected]) Android - message part header parsing (parsePartHeaders, multiple files)
Estimated exposure
massbillions of Android devices potentially affected (Android's global install base); exact count unknown — Android runs on an ecosystem of roughly three billion-plus active devices worldwide, so a flaw in a core Android parsing routine plausibly touches ecosystem-scale populations, though the data does not identify which builds carry the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.