CVE-2026-0021: High severity Google Android vulnerability
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0021?
CVE-2026-0021 is classified as a high severity vulnerability due to the potential for local escalation of privilege.
How do I fix CVE-2026-0021?
To fix CVE-2026-0021, it's essential to update to the latest version of Google Android that addresses this vulnerability.
What systems are impacted by CVE-2026-0021?
CVE-2026-0021 affects Google Android versions 14.0, 15.0, and 16.0, including specific beta releases.
Can CVE-2026-0021 be exploited without user interaction?
Yes, CVE-2026-0021 can be exploited without any user interaction, making it particularly concerning.
What type of vulnerability is CVE-2026-0021?
CVE-2026-0021 is a cross-user permission bypass vulnerability that arises from a confused deputy problem.