Executive brief
A security vulnerability has been identified in the Android operating system that could allow an attacker to access the private contacts database. This flaw could be used to gain elevated privileges on a device without requiring any interaction from the user. If exploited, it could lead to the unauthorized exposure of sensitive personal information or allow malicious software to gain deeper control over the phone.
Technical details
A SQL injection vulnerability exists within multiple functions of the Android System component. The flaw allows a local attacker to bypass security boundaries and access the contacts database, leading to an escalation of privilege (EoP). Exploitation does not require additional execution privileges or any user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. Google has addressed this issue in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.