CVE-2026-0096: High severity Google Android vulnerability
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Correct getAppLabel in ForgetDeviceDialogFragment.java to ensure the Forget Device dialog presents an unambiguous, non-misleading app/device label and context so users cannot be tricked into forgetting a device.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0096?
The severity of CVE-2026-0096 is high, with a CVSS score of 7.8.
How do I fix CVE-2026-0096?
To fix CVE-2026-0096, update your Google Android device to the latest security patches provided by Google.
What does CVE-2026-0096 affect?
CVE-2026-0096 affects Google Android and pertains to the ForgetDeviceDialogFragment functionality.
What is the risk of exploitation for CVE-2026-0096?
The risk of exploitation for CVE-2026-0096 is significant, as it allows for local escalation of privilege without user interaction.
How can CVE-2026-0096 be exploited?
CVE-2026-0096 can be exploited by misleading users into forgetting a device through insufficient UI cues.