CVE-2026-0012
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:37
- Zuletzt bearbeitet 06.03.2026 04:16:03
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...
CVE-2026-0011
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:36
- Zuletzt bearbeitet 06.03.2026 04:16:03
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVE-2026-0010
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:35
- Zuletzt bearbeitet 06.03.2026 04:16:03
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2026-0008
- EPSS 0.01%
- Veröffentlicht 02.03.2026 18:42:34
- Zuletzt bearbeitet 03.03.2026 13:20:00
In multiple locations, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0007
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:33
- Zuletzt bearbeitet 06.03.2026 04:16:02
In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVE-2026-0006
- EPSS 0.04%
- Veröffentlicht 02.03.2026 18:42:32
- Zuletzt bearbeitet 06.03.2026 04:16:02
In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0005
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:31
- Zuletzt bearbeitet 06.03.2026 04:16:02
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information ...
CVE-2025-48654
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:29
- Zuletzt bearbeitet 06.03.2026 04:16:01
In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...
CVE-2025-48653
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:28
- Zuletzt bearbeitet 06.03.2026 04:16:01
In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...
CVE-2025-48650
- EPSS 0%
- Veröffentlicht 02.03.2026 18:42:27
- Zuletzt bearbeitet 06.03.2026 04:16:01
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.