Junglewise Threat Intelligence

CVE-2026-0057: Google Android information disclosure in Contacts Provider

CVE-2026-0057 · Severity: low · CVSS 3.3 · Published 2026-06-17

Technologies: Google Android. Vendors: Google.

Executive brief

A security flaw in the Android Contacts Provider could allow a malicious local application to access sensitive information about incoming calls, including phone numbers and related metadata. This component is responsible for managing contact information and call logs on the device. An exploit could lead to unauthorized tracking of a user's communication history without their permission.

Technical details

An information disclosure vulnerability exists in the Android Contacts Provider component due to a missing authorization check (CWE-862). A local attacker can exploit this flaw to retrieve an incoming call's phone number and associated metadata without possessing the required system permissions. The vulnerability does not require additional execution privileges or complex user interaction, though some CVSS vectors suggest minimal user interaction may be involved. The issue is addressed in the Android 17 security patch level 2026-07-01.

Affected products

  • Google Android 17

Timeline

  • 2026-06-16: advisory: Android 17 Security Release Notes published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats