Junglewise Threat Intelligence

CVE-2026-0087: Google Android Framework privilege escalation in DomainVerificationService

CVE-2026-0087 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A logic error in the Android Framework allows a malicious application to hijack app links, which are the shortcuts that automatically open specific apps when a user clicks a web URL. By exploiting this flaw, an attacker could intercept sensitive data or redirect users to a fraudulent application without any user interaction. This could lead to an unauthorized elevation of privileges on the affected device.

Technical details

A logic error exists within the 'approvalLevelForDomainInternal' method of 'DomainVerificationService.java' in the Android Framework. This vulnerability allows a local attacker to hijack arbitrary app links (Android App Links), which are intended to associate specific web domains with verified applications. By manipulating the domain verification logic, a malicious app can intercept intents meant for other applications. Exploitation does not require additional execution privileges or user interaction. The issue affects Android versions 14, 15, 16, and 16-qpr2, and is addressed in the June 2026 security patch level.

Affected products

  • Google Android Framework 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in the June 2026 Android Security Bulletin.
  • 2026-06-01: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats