Junglewise Threat Intelligence

CVE-2026-0093: Google Android privilege escalation via UI obfuscation in System component

CVE-2026-0093 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system could allow a malicious application to gain elevated system privileges. This occurs because certain parts of the user interface can be obscured or misleading, potentially tricking the system into performing unauthorized actions. If exploited, an attacker could gain deeper access to the device's data and functions without requiring any special permissions or user interaction.

Technical details

A local escalation of privilege (EoP) vulnerability exists in the Android System component (specifically tracked as A-473812391). The root cause is a misleading user interface caused by obfuscation in multiple locations within the OS. An attacker can exploit this flaw to gain elevated execution privileges on the device. Notably, the exploit requires no additional execution privileges and functions without any user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2, and is addressed in the June 2026 security patch level.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats