CVE-2026-0020: High severity Google Android vulnerability
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0020?
CVE-2026-0020 has been rated as a critical severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2026-0020?
To fix CVE-2026-0020, it is recommended to update to the latest version of Android that addresses this vulnerability.
What software versions are affected by CVE-2026-0020?
CVE-2026-0020 affects Google Android versions 14.0, 15.0, and 16.0 across various builds.
Is user interaction required to exploit CVE-2026-0020?
No, user interaction is not needed to exploit CVE-2026-0020, making it particularly concerning.
What type of vulnerability is CVE-2026-0020 classified as?
CVE-2026-0020 is classified as a permissions bypass vulnerability that can lead to local escalation of privilege.