Executive brief
A security flaw in Android's lock screen management allows an unauthorized person with physical access to a device to bypass 'lockdown mode' when screen pinning is active. This could allow someone to view sensitive information on the device without knowing the passcode. The issue is caused by a logic error in how the system handles secure lock states.
Technical details
A logic error exists within multiple functions of KeyguardViewMediator.java in the Android System component. This vulnerability allows an attacker with local access to bypass the 'lockdown mode' security feature when screen pinning is in use. Exploitation does not require additional execution privileges or user interaction. Successful exploitation results in local information disclosure by circumventing intended keyguard restrictions. The issue is addressed in the June 2026 Android Security Bulletin with patch levels 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed in June 2026 Android Security Bulletin
- 2026-06-01: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue