Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.2

AppOpsService Java Code May Crash with Malicious Input

CVE-2026-0015 ASB-A-445917646
Summary

A flaw in the AppOpsService Java code can cause a software crash if it receives malicious input. This could happen without anyone needing to interact with the system. To protect against this issue, ensure proper input validation is implemented in the AppOpsService Java code.

What to do
  • Update google platform/frameworks/base to version 16-qpr2-next:2026-03-01.
  • Update google platform/frameworks/base to version 15:2026-03-01.
  • Update google platform/frameworks/base to version 16:2026-03-01.
  • Update google platform/frameworks/base to version 16-qpr2:2026-03-01.
  • Update google platform/frameworks/base to version 14:2026-03-01.
Affected software
VendorProductAffected versionsFix available
google android 14.0
google android 15.0
google android 16.0
google android 16.0
google android 16.0
google android 16.0
google platform/frameworks/base > 16-qpr2-next:0 , <= 16-qpr2-next:2026-03-01 16-qpr2-next:2026-03-01
google platform/frameworks/base > 15:0 , <= 15:2026-03-01 15:2026-03-01
google platform/frameworks/base > 16:0 , <= 16:2026-03-01 16:2026-03-01
google platform/frameworks/base > 16-qpr2:0 , <= 16-qpr2:2026-03-01 16-qpr2:2026-03-01
google platform/frameworks/base > 14:0 , <= 14:2026-03-01 14:2026-03-01
Original title
In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional executi...
Original description
In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd CVSS3.1 6.2
Vulnerability type
CWE-20 Improper Input Validation
Published: 1 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026