No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Misleading KeyChainActivity UI Enables Local Privilege Escalation | |
| First Time appeared |
Google
Google android |
|
| Weaknesses | CWE-250 CWE-269 CWE-749 |
|
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2026-06-01T22:59:47.636Z
Reserved: 2025-10-15T15:42:54.883Z
Link: CVE-2026-0094
Updated: 2026-06-01T22:59:39.404Z
Status : Received
Published: 2026-06-01T22:16:22.927
Modified: 2026-06-01T23:16:17.250
Link: CVE-2026-0094
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:45:25Z