CVE-2026-0097: High severity Google Android vulnerability
Published Jun 1, 2026
·Updated
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Jun 1, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0097?
The severity of CVE-2026-0097 is classified as high with a CVSS score of 8.
2
How do I fix CVE-2026-0097?
To fix CVE-2026-0097, you should update your Google Android devices to the latest security patch provided.
3
What are the potential impacts of CVE-2026-0097?
The potential impacts of CVE-2026-0097 include remote escalation of privilege due to a logic error in pairing LE devices.
4
Is user interaction required to exploit CVE-2026-0097?
No, user interaction is not needed for exploitation of CVE-2026-0097.
5
Which software is affected by CVE-2026-0097?
CVE-2026-0097 affects Google Android devices.