CVE-2026-0023
- EPSS 0.08%
- Veröffentlicht 02.03.2026 18:42:45
- Zuletzt bearbeitet 06.03.2026 04:16:04
In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVE-2026-0021
- EPSS 0.1%
- Veröffentlicht 02.03.2026 18:42:43
- Zuletzt bearbeitet 06.03.2026 04:16:04
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2026-0020
- EPSS 0.1%
- Veröffentlicht 02.03.2026 18:42:42
- Zuletzt bearbeitet 06.03.2026 04:16:04
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges need...
CVE-2026-0017
- EPSS 0.1%
- Veröffentlicht 02.03.2026 18:42:41
- Zuletzt bearbeitet 01.10.2026 08:16:50
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVE-2026-0015
- EPSS 0.09%
- Veröffentlicht 02.03.2026 18:42:40
- Zuletzt bearbeitet 06.03.2026 04:16:04
In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed ...
CVE-2026-0014
- EPSS 0.09%
- Veröffentlicht 02.03.2026 18:42:39
- Zuletzt bearbeitet 27.09.2026 06:16:54
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not need...
CVE-2026-0013
- EPSS 0.09%
- Veröffentlicht 02.03.2026 18:42:38
- Zuletzt bearbeitet 26.08.2026 19:16:47
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...
CVE-2026-0012
- EPSS 0.1%
- Veröffentlicht 02.03.2026 18:42:37
- Zuletzt bearbeitet 26.08.2026 19:16:46
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...
CVE-2026-0011
- EPSS 0.11%
- Veröffentlicht 02.03.2026 18:42:36
- Zuletzt bearbeitet 26.08.2026 19:16:46
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVE-2026-0010
- EPSS 0.1%
- Veröffentlicht 02.03.2026 18:42:35
- Zuletzt bearbeitet 08.09.2026 19:17:49
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...