Junglewise Threat Intelligence

CVE-2026-0088: Google Android privilege escalation in CertInstaller

CVE-2026-0088 · Severity: info · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android System component could allow a malicious application to hide or misrepresent sensitive security dialogues. This component is responsible for installing digital certificates, and a flaw here could trick a user or the system into granting elevated permissions. An attacker could use this to gain higher-level access to the device without needing any special permissions or direct user interaction.

Technical details

A vulnerability in the 'getCallingAppLabel' method of CertInstaller.java within the Android System component stems from misleading or insufficient UI handling. This flaw allows a local attacker to bypass or hide sensitive security dialogues during certificate installation processes. The vulnerability is classified as Elevation of Privilege (EoP) and can be exploited locally without any prior execution privileges or user interaction. Google has addressed this in the June 2026 Android Security Bulletin, with fixes available for Android versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
  • 2026-06-01: advisory

References

Related threats