CVE-2026-0046: Medium severity Google Android vulnerability
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0046?
CVE-2026-0046 has a medium severity rating of 6.2 according to the CVSS 3.1 metrics.
What is CVE-2026-0046 about?
CVE-2026-0046 involves a tapjacking/overlay attack in InputInterceptor of Letterbox.java, allowing possible local escalation of privilege.
How does CVE-2026-0046 affect Google Android users?
CVE-2026-0046 can potentially trick users into accepting permissions without their knowledge, leading to security risks.
Who is affected by CVE-2026-0046?
Any users of Google Android devices that utilize the affected versions with the vulnerable InputInterceptor implemented are at risk.
How can I fix CVE-2026-0046?
To mitigate CVE-2026-0046, users should update their Google Android devices to the latest patched version released by Google.