10
CVE-2026-28576
- EPSS 0.15%
- Veröffentlicht 17.06.2026 07:19:47
- Zuletzt bearbeitet 17.06.2026 07:19:47
- Quelle baff130e-b8d5-4e15-b3d3-c3cf5d
- CVE-Watchlists
- Unerledigt
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAndroid
≫
Produkt
Android
Default Statusunaffected
Version
17
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.044 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| baff130e-b8d5-4e15-b3d3-c3cf5d5545c6 | 10 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
|
https://source.android.com/docs/security/bulletin/android-17