CVE-2026-0092
CVE-2026-0092 is a critical-severity vulnerability in Google Android with a CVSS 4.0 base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Critical (CVSS 4.0 base score 10.0)
- EPSS exploit prediction: 0% (11th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-37564
- Weakness: CWE-862
- Affected product: Google Android
- Published:
- Last modified:
Description
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Frequently asked questions
- What is CVE-2026-0092?
- In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- How severe is CVE-2026-0092?
- CVE-2026-0092 has a CVSS 4.0 base score of 10.0, rated critical severity.
- Is CVE-2026-0092 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (11th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-0092?
- CVE-2026-0092 affects Google Android. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-0092?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-0092 have an EU (EUVD) identifier?
- Yes. CVE-2026-0092 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-37564.
- When was CVE-2026-0092 published?
- CVE-2026-0092 was published on 2026-06-17 and last updated on 2026-06-18.
References
Affected products (1)
- cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*
More vulnerabilities in Google Android
- CVE-2025-48611 — Critical (CVSS 10.0): In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead…
- CVE-2015-8073 — Critical (CVSS 10.0): mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a…
- CVE-2015-8072 — Critical (CVSS 10.0): mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute…
- CVE-2015-6610 — Critical (CVSS 10.0): libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a…
- CVE-2015-6609 — Critical (CVSS 10.0): libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or…
- CVE-2015-6608 — Critical (CVSS 10.0): mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary…
All CVEs affecting Google Android →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-101000 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
- CVE-2026-97360 — Critical (CVSS 10.0): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows…
- CVE-2026-65381 — Critical (CVSS 10.0): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the…
- CVE-2026-81648 — Critical (CVSS 10.0): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX…
- CVE-2026-77770 — Critical (CVSS 10.0): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a…
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-862 (Missing Authorization) vulnerabilities →