In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://source.android.com/docs/security/bulletin/2026/2026-06-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-01 22:16
Updated : 2026-07-22 17:10
NVD link : CVE-2026-0094
Mitre link : CVE-2026-0094
CVE.ORG link : CVE-2026-0094
JSON object : View
Products Affected
- android
CWE
CWE-451
User Interface (UI) Misrepresentation of Critical Information
