Executive brief
A logic error in the Android Framework allows a malicious application to hijack app links, which are the shortcuts that automatically open specific apps when a user clicks a web URL. By exploiting this flaw, an attacker could intercept sensitive data or redirect users to a fraudulent application without any user interaction. This could lead to an unauthorized elevation of privileges on the affected device.
Technical details
A logic error exists within the 'approvalLevelForDomainInternal' method of 'DomainVerificationService.java' in the Android Framework. This vulnerability allows a local attacker to hijack arbitrary app links (Android App Links), which are intended to associate specific web domains with verified applications. By manipulating the domain verification logic, a malicious app can intercept intents meant for other applications. Exploitation does not require additional execution privileges or user interaction. The issue affects Android versions 14, 15, 16, and 16-qpr2, and is addressed in the June 2026 security patch level.
Affected products
- Google Android Framework 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability published in the June 2026 Android Security Bulletin.
- 2026-06-01: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.