LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-0006 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 3, 2026

Affected software - Remote Code Execution

Published: March 2, 2026Updated: March 3, 2026PoC AvailableRemote Exploitable

Overview

Affected software contains a heap buffer overflow causing out of bounds read and write, letting remote attackers execute arbitrary code without additional privileges, exploit requires no user interaction.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 9.4%(Probability of exploitation in next 30 days)

Impact

Remote attackers can execute arbitrary code, potentially leading to full system compromise.

Mitigation

Update to the latest version.

Social Media Activity(3 posts)

BeyondMachines :verified:
BeyondMachines :verified:
@beyondmachines1
Mar 3, 2026

Google Android March 2026 Security Bulletin Patches 129 Vulnerabilities, One Actively Exploited Qualcomm Flaw Google's March 2026 Android Security Bulletin patches 129 vulnerabilities, including a critical RCE flaw (CVE-2026-0006) requiring no user interaction and multiple CVSS 9.0 privilege escalation bugs in the kernel virtualization layer. A Qualcomm Display component vulnerability (CVE-2026-21385) is already being actively exploited in targeted attacks in the wild. **An critical update for Android, with actively exploited flaw patched. Most users can't rush the patch because their vendors may not have released an updated version of Android for their devices. Do not delay the update to your Android when the you see the alert that an update is available. Your device may be targeted via the Qualcomm flaw.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/march-2026-android-security-bulletin-patches-129-vulnerabilities-one-actively-exploited-qualcomm-flaw-s-u-0-2-i/gD2P6Ple2L

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 3, 2026

šŸ”“ CVE-2026-0006 - Critical (9.8) In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-0006/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
Offensive Sequence
Offensive Sequence
@offseq
Mar 3, 2026

šŸ”“ CVE-2026-0006: CRITICAL RCE in Android 16 via heap buffer overflows. No user action or privileges needed — remote attackers can fully compromise devices. Patch urgently when available! https://radar.offseq.com/threat/cve-2026-0006-remote-code-execution-in-google-andr-79236030 #OffSeq #Android #RCE #Vulnerability

View original post

Details

CVE ID
CVE-2026-0006
Severity
Critical
CVSS Score
9.8
Type
buffer_overflow
Status
confirmed
EPSS
9.4%
Social Posts
3

CWE

  • CWE-122

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

9.4%Probability of exploitation in the next 30 days