Junglewise Threat Intelligence

CVE-2026-0019: Google Android SettingsLib privilege escalation via system component disabling

CVE-2026-0019 · Severity: high · CVSS 7.8 · Published 2026-06-17

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android SettingsLib component allows for the unauthorized disabling of critical system components. This could enable a local attacker to gain elevated system privileges without any user interaction. Such an exploit could compromise device security, lead to data access, or disrupt normal operations.

Technical details

A logic error exists within the SettingsLib component of Android 17, classified as Improper Privilege Management (CWE-269). This vulnerability allows a local attacker with low privileges to disable system components, leading to a full escalation of privilege (EoP). The attack does not require additional execution privileges or user interaction. The issue is addressed in the Android 17 security release with a patch level of 2026-07-01 or later.

Affected products

  • Google Android 17

Timeline

  • 2026-06-16: advisory: Android 17 Security Release Notes published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats