CVE-2026-0005: Infoleak
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0005?
CVE-2026-0005 has a medium severity rating due to its potential for local information disclosure.
How do I fix CVE-2026-0005?
Fixing CVE-2026-0005 requires updating to the latest security patch provided by Google for affected Android versions.
What are the affected software versions for CVE-2026-0005?
CVE-2026-0005 affects Google Android versions 14.0, 15.0, and 16.0.
What type of vulnerability is CVE-2026-0005?
CVE-2026-0005 is a partial bypass vulnerability related to app pinning and permission checks.
Can CVE-2026-0005 be exploited remotely?
CVE-2026-0005 cannot be exploited remotely as it requires local access to the affected device.