CVE-2026-0061: Medium severity Google Android vulnerability
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0061?
The severity of CVE-2026-0061 is classified as medium with a CVSS score of 5.9.
How do I fix CVE-2026-0061?
To mitigate CVE-2026-0061, ensure that your device is updated to the latest security patches released by Google.
What is the risk of CVE-2026-0061?
CVE-2026-0061 has a risk level of 42, indicating a potential for significant impact if exploited.
What type of attack is associated with CVE-2026-0061?
CVE-2026-0061 is associated with a tapjacking or overlay attack that can trick users into granting permissions.
Does CVE-2026-0061 require user interaction to exploit?
No, CVE-2026-0061 can be exploited without any user interaction.