CVE-2026-0017: [NotCVE-2026-0017] game-music-emu (libgme) 0.6.5 and Earlier AY Loader NULL Pointer Defence Allows Denial of Service
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0017?
The severity of CVE-2026-0017 is classified as a moderate risk due to potential local escalation of privilege.
How do I fix CVE-2026-0017?
To fix CVE-2026-0017, users should update their Android device to the latest version where the vulnerability has been patched.
What could happen if CVE-2026-0017 is exploited?
If CVE-2026-0017 is exploited, it could allow unauthorized access to fingerprint unlock features, leading to unauthorized actions on the device.
Who is affected by CVE-2026-0017?
CVE-2026-0017 affects devices running Android 16.0 and its beta versions, including qpr2_beta_1, qpr2_beta_2, and qpr2_beta_3.
Is user interaction required to exploit CVE-2026-0017?
No, user interaction is not required to exploit CVE-2026-0017, making it particularly concerning.