CVE-2026-0019High· 7.8▾ TwilightIn SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
android = 17.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0179Medium· 6.7In Bootloader, there is a possible permission bypass due to a missing permission check
CVE-2026-0009High· 7.8In multiple locations, there is a possible tapjacking due to a logic error in the code
CVE-2026-0091High· 7.8In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user
CVE-2026-0089High· 7.8In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check
CVE-2026-0086Medium· 6.8In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check
CVE-2026-96812High· 8.8Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achi…