Junglewise Threat Intelligence

CVE-2026-0098: Google Android privilege escalation in Shared.java

CVE-2026-0098 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability in the Android operating system could allow a malicious application to bypass restrictions on starting activities. This is caused by a 'confused deputy' flaw where the system incorrectly identifies the source of a request. If exploited, a local attacker could gain elevated privileges on the device without any interaction from the user.

Technical details

A confused deputy vulnerability exists in the 'getCallingPackageName' method within 'Shared.java' of the Android System component. The flaw allows a malicious application to bypass activity start restrictions by misrepresenting its identity to the system. This vulnerability can be exploited locally without requiring any special execution privileges or user interaction. Successful exploitation leads to local escalation of privilege (EoP). The issue is addressed in the June 2026 Android Security Bulletin with security patch level 2026-06-05.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats