Executive brief
A security vulnerability in Android devices could allow a malicious application to trick users into granting sensitive permissions. By using a "tapjacking" or overlay attack, an attacker can place a hidden or misleading visual layer over the system's permission dialogs, leading a user to unintentionally click "allow." This could result in an unauthorized app gaining access to private data or system functions.
Technical details
A vulnerability exists in multiple functions of WindowState.java within the Android Framework. The flaw enables a tapjacking or overlay attack where a malicious application can obscure or misrepresent the system's permission request UI. By overlaying a deceptive interface, the attacker can trick a user into interacting with the underlying permission dialog, leading to a local escalation of privilege (EoP). This issue affects Android versions 14, 15, 16, and 16-qpr2. A fix is available in the June 2026 Android Security Bulletin (patch level 2026-06-05).
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.