CVE-2026-22104 — Google Android
As of 2026-03-05, CVE-2026-22104 is a CRITICAL-severity vulnerability in Google Android, CVSS v3.1 9.8, EPSS 91.2% (98.6th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2026-22104, most recently “Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112)”.
Last updated: 2026-03-05
What is CVE-2026-22104?
A type confusion vulnerability exists in the Android Runtime (ART) dex2oat ahead-of-time compiler affecting Android 12 through 15. When processing a specially crafted APK containing malformed DEX bytecode, the ART runtime incorrectly handles type resolution during compilation, allowing an attacker to corrupt the vtable of a managed object and redirect virtual method dispatch to attacker-controlled native code. Successful exploitation achieves remote code execution within the target application process context. Google TAG identified active exploitation by commercial spyware vendor Saito Tech (formerly Candiru) as Stage 1 of a 3-stage exploit chain targeting journalists, activists, and political dissidents in the Middle East and Southeast Asia. The crafted APK can be delivered via watering hole attacks, malicious ad injection leveraging the Sherlock ad-based delivery mechanism, or social engineering links.
The record classifies CVE-2026-22104 under weakness class CWE-843. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs a user to take an action first, and has high impact on confidentiality, integrity, availability. 4 affected-product entries are recorded, across 3 vendors, listed below. The identifier was first published 205 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.8 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS (FIRST)
- 91.2% probability of exploitation in the next 30 days, higher than 98.6% of all scored CVEs
- CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 8.8/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2026-02-20, last modified 2026-03-05
Is CVE-2026-22104 being exploited?
It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.
Affected products and versions
- Google: Android, Android Runtime (ART)
- Qualcomm: Snapdragon Mobile Platforms
- MediaTek: Dimensity / Helio SoCs
How to fix CVE-2026-22104
The record marks a vendor fix as available for CVE-2026-22104. Patch reference: https://source.android.com/docs/security/bulletin/2026/2026-03-01. Vendor advisory: https://source.android.com/docs/security/bulletin/2026/2026-03-01. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2026-22104
1 tracked threat in the Threadlinqs corpus references CVE-2026-22104, either in the campaign’s CVE list or as an indicator on the campaign record.
- Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112) — CRITICAL · 2026-03-06
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence