CVE-2026-0009
Tapjacking Vulnerability in Android OS
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a tapjacking issue caused by a logic error in multiple locations within the code. Tapjacking is a technique where an attacker tricks a user into tapping on something different from what the user perceives, potentially leading to unauthorized actions.
In this case, the vulnerability allows for local escalation of privilege without requiring any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker could escalate their privileges locally on the affected system without needing to execute additional code or require user interaction.
This means an attacker with limited access could gain higher privileges, potentially leading to unauthorized access or control over system functions.