Description
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic error in Android’s tap handling code creates a potential tapjacking flaw that can enable local privilege escalation without the need for additional execution privileges. Because user interaction is not required, the flaw can be exploited by triggering the logic error through a malicious user interface component, allowing an attacker to perform privileged actions as if they were a trusted application.

Affected Systems

The vulnerability is found in Google’s Android operating system. No specific vendor or version details are given, so any Android device running an unpatched build that contains the identified logic error may be affected. All devices with the affected code paths remain potentially vulnerable until a fix is applied.

Risk and Exploitability

The Exploit Prediction Scoring System score is not available and the vulnerability is not listed in CISA KEV. The flaw provides local privilege escalation, which would grant an attacker the same level of permission as the affected privileged component. Based on the description, it is inferred that an attacker could trigger the logic error by installing or interacting with an application capable of presenting an overlay or malicious UI component; this would bypass the need for user interaction. Given the high impact of LPE and the lack of guardrails, the security risk is significant in environments where additional privileges are granted to apps that can display overlays or otherwise influence touch input.

Generated by OpenCVE AI on June 1, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Android to the latest security patch released by Google
  • Restrict or disable overlay permissions for applications that are not essential for device operation
  • Audit installed applications for high‑privilege or overlay capabilities and remove or reconfigure those that are unnecessary or untrusted

Generated by OpenCVE AI on June 1, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Logic Error Allows Local Privilege Escalation via Tapjacking on Android
Weaknesses CWE-272
CWE-739

Mon, 01 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T21:14:51.028Z

Reserved: 2025-10-15T15:38:37.612Z

Link: CVE-2026-0009

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-01T22:16:19.173

Modified: 2026-06-01T22:16:19.173

Link: CVE-2026-0009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T23:00:16Z

Weaknesses