Executive brief
A vulnerability in the Android operating system could allow a malicious application to trick users into granting sensitive permissions. By using a 'tapjacking' or overlay attack, an attacker can hide or disguise permission prompts, leading users to unintentionally authorize access to private data or system functions. This could result in an unauthorized elevation of privileges on the affected device.
Technical details
A vulnerability exists in the 'hide' method of WindowState.java within the Android Framework. The flaw enables a tapjacking or overlay attack, where a malicious application can overlay a deceptive UI over a legitimate system permission dialog. This allows an attacker to intercept user interactions and trick the user into granting elevated permissions without their knowledge. The vulnerability is classified as Elevation of Privilege (EoP) and can be exploited locally without requiring additional execution privileges. Google has addressed this issue in the June 2026 Android Security Bulletin for Android versions 14, 15, and 16.
Affected products
- Google Android Framework 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-05: patched: Security patch levels of 2026-06-05 or later address this issue.