CVE-2026-0075PoC(google / android)

MEDIUMCVSS 5.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Peaked 1d ago at 3 mentions (2026-08-19); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-14: 2Mentions · 2026-08-19: 3Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-14: 2PoC Mentioned / Linked · 2026-08-19: 3PoC Mentioned / Linked · 2026-08-21: 1Exploit Tool / Code · 2026-08-14: 2Exploit Tool / Code · 2026-08-19: 3Exploit Tool / Code · 2026-08-21: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-14: 2Technical Details · 2026-08-19: 3Technical Details · 2026-08-21: 108-1408-1908-21
Signal classification2 categories
PoC
583.3%
Exploit
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-142
Exploit1PoC1
2026-08-193
PoC3
2026-08-211
PoC1
Full discourse6 posts
  • Dark Web Intelligence@DailyDarkWeb
    PoC

    🚨 Public PoC Released for Android Vulnerability CVE-2026-0075 Security researcher QM4RS has released a public proof-of-concept for CVE-2026-0075, a high-severity vulnerability affecting Android's ContactsProvider component. * CVE-2026-0075 affects Android 14, 15, 16 and 16 QPR2 * Google classifies the vulnerability as High severity * The vulnerability involves SQL injection in ContactsProvider and could allow unauthorized access to contact database information * Exploitation does not require user interaction * The newly released research demonstrates the issue without requesting READ_CONTACTS or WRITE_CONTACTS permissions * The researcher notes that the PoC is build-specific and should not be interpreted as universal exploitation across every Android device * Google addressed CVE-2026-0075 in the June 2026 Android security updates The vulnerability itself is not new. The important development is the public release of PoC code, which lowers the barrier for researchers and potentially malicious actors to reproduce and investigate the flaw. Organizations managing Android fleets should verify that affected devices are running the June 5, 2026 security patch level or later. Original PoC: https://github.com/QM4RS/CVE-2026-0075 Official Google Advisory: https://source.android.com/docs/security/bulletin/2026-06-01 #DDW #Android #CyberSecurity #CVE20260075 #Vulnerability #PoC #MobileSecurity

    Post summary

    The primary focus is the public release of a PoC for CVE-2026-0075, detailing a SQL injection in Android’s ContactsProvider, with an available patch from June 2026.

    015057308.8K
    205.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 Public PoC available for high-severity Android ContactsProvider flaw https://github.com/qm4rs/cve-2026-0075 CVE-2026-0075 affects Android 14, 15, 16, and 16 QPR2 and can allow access to information from the contacts database through a SQL-related side channel without user interaction. Researcher QM4RS has now released a controlled Android PoC that intentionally requests neither READ_CONTACTS nor WRITE_CONTACTS. The issue involves ContactsProvider2 returning detailed SQLite errors to callers that lack contacts permission. Those errors could potentially be abused as an information side channel. Google's fix strips sensitive JSON-related SQLite exception details from unauthorized callers. The researcher cautions that the PoC is build-specific and does not demonstrate a universal exploitation path across every Android device. Devices with the June 5, 2026 Android security patch level or later address the issue.

    Post summary

    The post shares a publicly available PoC for CVE‑2026‑0075, details a SQL‑based side‑channel flaw in Android’s ContactsProvider, and notes that Google’s June 5, 2026 patch resolves the issue.

    37057209.6K
    240.1K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 PoC RELEASED: Public exploit code is available for CVE-2026-0075, a high-severity Android SQL injection vulnerability. The flaw can expose the contacts database and lead to local privilege escalation, with no user interaction required. Affected versions include Android 14, 15, 16 and 16 QPR2. 🔗 https://github.com/qm4rs/cve-2026-0075 #Android #Google #CVE #PoC #CyberSecurity #MobileSecurity #Infosec

    Post summary

    A public proof‑of‑concept exploit for CVE‑2026‑0075 has been released, demonstrating an Android SQL injection that can read the contacts database and achieve local privilege escalation without user interaction.

    07037212.8K
    1.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-0075 Vendor: Google Product: Android Description: In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Link: https://github.com/qm4rs/cve-2026-0075 #dbugs_vuln

    Post summary

    A publicly available PoC/exploit demonstrates local privilege escalation via an Android contacts database SQL injection (CVE-2026-0075), with a GitHub repository linked, but no patch or active exploitation reported.

    02130113.3K
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A public PoC for CVE-2026-0075 exposes an Android elevation of privilege in ContactsProvider2 with no user interaction. Details are now disclosed. #CVE20260075 #Android #ElevationOfPrivilege #ContactsProvider #SQLInjection #AndroidSecurity https://securityonline.info/cve-2026-0075-android-eop/

    Post summary

    A publicly available PoC for CVE‑2026‑0075 demonstrates an Android elevation‑of‑privilege flaw in ContactsProvider2 that requires no user interaction, with technical details disclosed but no evidence of active exploitation or patch availability.

    14062591
    13.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Android ContactsProvider açığı için PoC yayınlandı. CVE-2026-0075; Android 14, 15, 16 ve 16 QPR2 sürümlerindeki ContactsProvider2 bileşenini etkiliyor. Açık, rehber erişim izni ('READ_CONTACTS' / 'WRITE_CONTACTS') olmayan bir uygulamanın ayrıntılı SQLite hatalarını bir side-channel olarak kullanarak Contacts veritabanı hakkında bilgi elde etmesine yol açabiliyor. Araştırmacı QM4RS tarafından public bir PoC yayınlandı. Ancak PoC'nin build-specific olduğu ve tüm Android cihazlarında çalışan evrensel bir exploit olmadığı özellikle belirtiliyor. 🛡️ 2026-06-05 veya daha yeni Android Security Patch Level kullanan cihazlar bu açık için yamalanmış durumda. PoC: https://github.com/qm4rs/cve-2026-0075

    Post summary

    A PoC for CVE-2026-0075 is publicly released and build‑specific, the vulnerability is detailed, and recent Android security patches already mitigate the issue.

    00000236
    1.8K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--
OSgoogleandroid16.0--

Explore more