Junglewise Threat Intelligence

CVE-2026-0094: Google Android UI deception in KeyChainActivity

CVE-2026-0094 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android system's certificate management component could allow a malicious application to trick users into granting access to sensitive security certificates. By presenting misleading information in the user interface, an attacker could gain unauthorized access to encrypted data or authentication credentials. This issue can be exploited without any special privileges or direct user interaction with the malicious code.

Technical details

A vulnerability in the 'getApplicationLabel' method of 'KeyChainActivity.java' within the Android System component allows for local escalation of privilege. The flaw stems from insufficient or misleading UI presentation, which can be leveraged to trick the system or user into approving certificate access requests. Despite being a UI-related issue, the advisory notes that user interaction is not required for exploitation, suggesting a bypass of the intended confirmation logic. This allows a local attacker to gain elevated privileges and access sensitive cryptographic material. Patches are available in the June 2026 Android Security Bulletin for AOSP versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability disclosed in June 2026 Android Security Bulletin
  • 2026-06-01: advisory: NVD record published

References

Related threats