Junglewise Threat Intelligence

CVE-2026-0016: Google Android Framework permissions bypass in CredentialManagerService

CVE-2026-0016 · Severity: info · CVSS 5.5 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android Credential Manager allows for a permissions bypass that could let an attacker access information across different user profiles on the same device. This component is responsible for managing user passwords and passkeys; an exploit could lead to the unauthorized disclosure of sensitive data. No user interaction is required for this attack to occur.

Technical details

A permissions bypass vulnerability exists in the 'updateProvidersWhenServiceRemoved' method within 'CredentialManagerService.java' of the Android Framework. The flaw allows an attacker to override settings across different user boundaries on a device. This can be exploited locally without any additional execution privileges or user interaction. Successful exploitation results in unauthorized information disclosure. The issue is addressed in the June 2026 Android Security Bulletin for AOSP versions 16 and 16-qpr2.

Affected products

  • Google Android Framework 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: advisory: NVD record published

References

Related threats