← Back to browse · API

CVE-2026-0092

Severity
CRITICAL
CVSS
10.0
EPSS
0.00218
Risk score
32.08
CISA KEV
No
PoC
Yes
Published
2026-06-17
Modified
2026-06-18
First seen
2026-08-07
Aliases
CNVD-2026-26392, EUVD-2026-37564, GHSA-WH9M-429C-P39P
Products
Google Android 17.0, Google:Android 17
Sources
github 465cdb13fa191f30343836c6|CVE-2026-0092
euvd EUVD-2026-37564
cnvd CNVD-2026-26392

Description

In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References