Junglewise Threat Intelligence

CVE-2026-0099: Google Android privilege escalation in HostEmulationManager

CVE-2026-0099 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android System component allows a background application to unexpectedly launch a visible interface (Activity). This could be used by a malicious app to trick users into performing actions or to escalate the app's privileges on the device. Exploitation requires the user to interact with the device, but the malicious app does not need any special permissions to start the attack.

Technical details

A logic error exists in the 'onNullBinding' method of HostEmulationManager.java within the Android System component. This flaw allows a background process to bypass restrictions and launch an activity, which can be leveraged for local escalation of privilege (EoP). The attack requires no additional execution privileges but does require user interaction to succeed. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. It is addressed in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Published in the June 2026 Android Security Bulletin
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats