CVE-2026-21027: Medium severity Google Android ImsSettings vulnerability
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SMR Jun-2026 Release 1 - Configuration
Prevent the affected components from being exported. Update the Android manifest for ImsSettings to ensure android:exported="false" for the affected components or remove intent-filters that cause them to be exported, so local attackers cannot trigger the logging function.
ImsSettings (Android application components) exported = false
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21027?
CVE-2026-21027 has a medium severity score of 4.8 according to the CVSS.
What type of vulnerability is CVE-2026-21027?
CVE-2026-21027 is classified as an improper export of Android application components.
Who is affected by CVE-2026-21027?
The vulnerability affects users of Google Android ImsSettings prior to the June 2026 Release 1.
How can CVE-2026-21027 be exploited?
Local attackers can exploit CVE-2026-21027 to trigger a logging function due to improper component export.
How do I fix CVE-2026-21027?
To mitigate CVE-2026-21027, users should update to the latest version of Google Android ImsSettings provided in the SMR Jun-2026 Release 1.