Junglewise Threat Intelligence

CVE-2026-0009: Google Android Framework tapjacking in multiple locations

CVE-2026-0009 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android Framework could allow a malicious application to perform 'tapjacking' attacks. This occurs when a hidden or misleading interface is layered over a legitimate one, tricking the system into granting elevated permissions or performing actions without the user's knowledge. If exploited, this could lead to a local escalation of privilege, potentially giving an attacker unauthorized access to sensitive device functions or data.

Technical details

A logic error exists in multiple locations within the Android Framework component that facilitates tapjacking. Tapjacking is a form of UI redressing where an attacker overlays a transparent or misleading UI element over a legitimate system dialog or application. In this specific case, the vulnerability allows for local escalation of privilege (EoP) without requiring any additional execution privileges or user interaction. The flaw is addressed in the June 2026 Android Security Bulletin for AOSP versions 15 and 16. Security patch levels of 2026-06-05 or later mitigate this issue.

Affected products

  • Google Android Framework 15, 16

Timeline

  • 2026-06-01: disclosed: Vulnerability disclosed in June 2026 Android Security Bulletin
  • 2026-06-01: advisory: NVD record published

References

Related threats