CVE-2026-21105: Collection vulnerability
Published Sep 9, 2026
·Updated
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
Affected Software
1 affected component
Collection<1.0.1.14, >1.0.1.14<
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.1.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.02.7
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access to an affected Android device. The issue is described as allowing local attackers to access sensitive information.
2
Which versions are affected?
Collection versions prior to 1.0.1.14 on Android 15 and prior to 2.0.02.7 on Android 16 are affected.