CVE-2026-0019: High severity Google SettingsLib vulnerability
Published Jun 17, 2026
·Updated
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google SettingsLib
Google Android=17.0
Event History
Jun 17, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0019?
CVE-2026-0019 has a risk score of 55, indicating a moderate level of severity.
2
How do I fix CVE-2026-0019?
To fix CVE-2026-0019, make sure to update to the latest version of Google SettingsLib that includes the security patch.
3
What systems are affected by CVE-2026-0019?
CVE-2026-0019 affects devices utilizing Google SettingsLib as part of their Android operating system.
4
Does CVE-2026-0019 require user interaction to be exploited?
No, CVE-2026-0019 does not require user interaction for exploitation.
5
What are the potential consequences of CVE-2026-0019?
The potential consequence of CVE-2026-0019 is local escalation of privilege, which could allow attackers to disable system components.