Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android Xr
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28659 1 Google 1 Android Xr 2026-09-14 N/A 7.8 HIGH
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0072 1 Google 1 Android Xr 2026-07-22 N/A 7.8 HIGH
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.