← Back to browse · API

CVE-2026-0072

Severity
CRITICAL
CVSS
10.0
EPSS
0.00122
Risk score
40.04
CISA KEV
No
PoC
No
Published
2026-06-01
Modified
2026-06-01
First seen
2026-08-05
Aliases
EUVD-2026-33728, GHSA-Q4X3-4F53-MG6Q
Products
Google:Android XR 14, google:android_xr
Sources
nvd CVE-2026-0072
euvd EUVD-2026-33728

Description

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References