PT-2026-45602 · Google · Android

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-0098

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A confused deputy issue exists in the getCallingPackageName() function of Shared.java. This flaw allows for the bypass of activity start restrictions, potentially leading to local escalation of privilege. Exploitation does not require user interaction or additional execution privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-0098

Affected Products

Android