CVE-2026-0094: High severity Google Android vulnerability
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0094?
The severity of CVE-2026-0094 is rated high with a CVSS score of 7.8.
How do I fix CVE-2026-0094?
To fix CVE-2026-0094, ensure that you have the latest security updates for Google Android installed.
What types of attacks does CVE-2026-0094 allow?
CVE-2026-0094 allows for local escalation of privilege through misleading UI that may trick users into approving certificate access.
Who is affected by CVE-2026-0094?
Users of Google Android devices are affected by CVE-2026-0094 due to the vulnerability in KeyChainActivity.java.
Is user interaction required for CVE-2026-0094 to be exploited?
User interaction is not required for CVE-2026-0094 to be exploited, making it particularly concerning.