Security
Security writeups
Vulnerability reports submitted to vendor disclosure programmes, published once their embargo has run. Each writeup sets out what was reported, the mechanism behind it, and how the vendor assessed it.
- Published
- 2
- Programme
- 1
- Since
- 2026
Unbounded notification bitmap offload to /data/system — storage-exhaustion DoS on Android 14–16
Android's notification bitmap offload path writes caller-supplied image data into the privileged /data/system partition. It applies no server-side bound on bitmap dimensions or byte size, no per-package quota and no total quota, and the…
Android & Google Devices VRPID 476317300Reported 2026-01-16TrustManagerService.isActiveUnlockRunning: the one Binder method in ITrustManager with no caller check
ITrustManager exposes sixteen Binder methods. Fifteen of them enforce something — a signature-level permission, an @EnforcePermission annotation, or a cross-user boundary check through ActivityManager.handleIncomingUser(). One does not.
Android & Google Devices VRPID 491430113Reported 2026-03-10
Findings still under coordinated disclosure are deliberately absent from this page. A report appears here only once the vendor has had the chance to respond and the embargo has ended.