CVE-2026-0057
Awaiting Analysis Awaiting Analysis - Queue
Contacts Provider Missing Permission Check Leads to Local Information Disclosure

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Android (associated with Google Inc. or Open Handset Alliance)

Description
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
android contacts_provider *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Contacts Provider component where there is a missing permission check that allows access to an incoming call's phone number and related metadata.

Because of this missing permission check, an attacker can locally disclose this information without needing any additional execution privileges or user interaction.

Impact Analysis

The vulnerability can lead to local information disclosure, meaning that sensitive data such as incoming call phone numbers and associated metadata could be accessed without proper authorization.

Since no additional privileges or user interaction are required, this could allow unauthorized parties to obtain private call information, potentially compromising user privacy.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0057. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart