Threat Intelligence / CVE / CVE-2026-22104

CVE-2026-22104

CVSS 9.8 (CRITICAL) · EPSS 91.3% · Published 2026-02-20

A type confusion vulnerability exists in the Android Runtime (ART) dex2oat ahead-of-time compiler affecting Android 12 through 15. When processing a specially crafted APK containing malformed DEX bytecode, the ART runtime incorrectly handles type resolution during compilation, allowing an attacker to corrupt the vtable of a managed object and redirect virtual method dispatch to attacker-controlled native code. Successful exploitation achieves remote code execution within the target application process context. Google TAG identified active exploitation by commercial spyware vendor Saito Tech (formerly Candiru) as Stage 1 of a 3-stage exploit chain targeting journalists, activists, and political dissidents in the Middle East and Southeast Asia. The crafted APK can be delivered via watering hole attacks, malicious ad injection leveraging the Sherlock ad-based delivery mechanism, or social engineering links.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)

CWE-843

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-22104 are available via the Threadlinqs MCP server (Purple tier). View plans →

Markdown version · Threadlinqs Intelligence