CVE-2026-0088: High severity Google Android CertInstaller vulnerability
In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0088?
CVE-2026-0088 has a high severity rating of 7.8 according to the CVSS 3.1 scoring system.
What is the main risk associated with CVE-2026-0088?
The main risk of CVE-2026-0088 is that it allows local escalation of privilege by hiding a sensitive security dialogue.
How do I mitigate CVE-2026-0088?
Mitigation for CVE-2026-0088 involves updating to the latest version of Google Android that addresses the vulnerability.
Who is affected by CVE-2026-0088?
CVE-2026-0088 affects users of Google Android, specifically those using the Google Android CertInstaller.
Is user interaction required to exploit CVE-2026-0088?
No, user interaction is not required to exploit CVE-2026-0088.