CVE-2026-0198: Medium severity Google Android vulnerability
Published Oct 6, 2026
·Updated
In ispdallowed of gemmsg.c, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 6, 2026
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires local System execution privileges. The available information does not establish that an unprivileged application can exploit it.
2
Does exploitation require any user interaction?
No. User interaction is not required for exploitation.