CVE-2026-0096
Forget Device UI Misleading Local Privilege Escalation
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-451 | The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the getAppLabel function of ForgetDeviceDialogFragment.java. It involves a misleading or insufficient user interface that could trick a user into forgetting a device unintentionally.
Because of this UI issue, an attacker could cause a local escalation of privilege without needing any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The impact of this vulnerability is a local escalation of privilege, meaning an attacker with local access could gain higher privileges on the device.
This could allow unauthorized changes related to device management, such as forgetting a device, potentially disrupting normal device operations or security settings.