← Back

CVE-2026-0094

nvd nist
Published: Jun 1, 2026Modified: Jul 22, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected (6)

Products: Google: Android
1 product
Android
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 14.0
Version 15.0
Version 16.0
Version 16.0 qpr2_beta_1
Version 16.0 qpr2_beta_2
Version 16.0 qpr2_beta_3

References (1)

Timeline

No history available yet.