Junglewise Threat Intelligence

CVE-2026-0072: Google Android InputMethodManagerService privilege escalation

CVE-2026-0072 · Severity: info · CVSS 10 · Published 2026-06-01

Vendors: Google.

Executive brief

A vulnerability in the Android XR platform's input management service could allow a local application to gain elevated privileges. This flaw allows an attacker to bypass security restrictions and potentially read sensitive input text without user permission. No user interaction is required for this exploit to succeed.

Technical details

A vulnerability exists in the 'addInputMethodListener' method of 'com.android.server.inputmethod.InputMethodManagerService' due to a missing permission check. This flaw allows a local attacker to achieve escalation of privilege (EoP) without requiring additional execution privileges or user interaction. Specifically, in the context of Android XR, this can lead to the unauthorized reading of input text. The issue is addressed in the 2026-06-01 security patch level for Android 14.

Affected products

  • Google Android XR 14

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: patched

References

Related threats