CVE-2026-0021Disclosure(google / android)

LOWCVSS 8.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-03: 2Technical Details · 2026-03-03: 203-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0021 Cross-User Permission Bypass in http://AppInfoBase.java Leads to Local Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0021

    Post summary

    The post announces CVE‑2026‑0021, a cross‑user permission bypass in AppInfoBase.java that allows local privilege escalation, with no mention of PoC, exploit, patch, or active exploitation.

    0000044
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-0021 - High In hasInteractAcrossUsersFullPermission of http://AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no... https://www.thehackerwire.com/vulnerability/CVE-2026-0021/ https://t.co/2SbM1F8oGF

    Post summary

    The post announces CVE‑2026‑0021, a high‑severity local privilege escalation via a permission bypass in AppInfoBase.java, but provides no PoC, exploit code, or patch details.

    0000057
    121 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--

Explore more