|
1261
|
3.3 |
LOW
Local
|
google
|
android
|
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-0056
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1262
|
7.8 |
HIGH
Local
|
google
|
android
|
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-28577
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1263
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with n…
|
NVD-CWE-noinfo
|
CVE-2026-0067
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1264
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additi…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0059
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1265
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no add…
|
NVD-CWE-noinfo
|
CVE-2026-0060
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1266
|
7.8 |
HIGH
Local
|
google
|
android
|
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege w…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-0096
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1267
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0097
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1268
|
7.8 |
HIGH
Local
|
google
|
android
|
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional ex…
|
CWE-441
Confused Deputy
|
CVE-2026-0098
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1269
|
7.8 |
HIGH
Local
|
google
|
android
|
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege wit…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2026-0099
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1270
|
7.8 |
HIGH
Local
|
google
|
android
|
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0100
|
2026-06-3 22:39 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|