Description
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the KeyChainActivity’s getApplicationLabel method can mislead users into approving certificates through an insufficient or deceptive interface. Because the certificate installation process can be executed without requiring the user to actively approve it, the attacker can gain elevated privileges on the device simply by having the certificate added. This escalation does not depend on additional execution privileges or external code execution; it leverages the trust model built into the Android certificate framework.

Affected Systems

Google Android devices that include the vulnerable KeyChainActivity component. The specific Android OS versions affected are not detailed in the available data, but the issue applies to any Android release that contains the vulnerable code path.

Risk and Exploitability

The CVSS score of 7.8 is available, and the EPSS score is unavailable, so the quantitative likelihood of exploitation cannot be determined. The vulnerability is local, requiring the attacker to have some form of access to the device. It is not currently listed in CISA’s KEV catalog. The attack could be executed without active user interaction, making it potentially easier to exploit in environments where users are convenience‑oriented or in kiosk scenarios. The impact is a local privilege escalation that could enable further malicious actions such as installing additional certificates or privileged applications.

Generated by OpenCVE AI on June 2, 2026 at 02:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure devices run the latest Android security patch level that addresses the KeyChainActivity UI issue.
  • In a managed environment, restrict certificate installation through enterprise MDM policies or require administrative approval for any new certificates.
  • Provide user training that emphasizes the risks of accepting unknown certificates and verifies the issuer before allowing installation.

Generated by OpenCVE AI on June 2, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Misleading KeyChainActivity UI Enables Local Privilege Escalation
Weaknesses CWE-250
CWE-269
CWE-749

Mon, 01 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title Misleading KeyChainActivity UI Enables Local Privilege Escalation
First Time appeared Google
Google android
Weaknesses CWE-250
CWE-269
CWE-749
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-02T03:56:20.008Z

Reserved: 2025-10-15T15:42:54.883Z

Link: CVE-2026-0094

cve-icon Vulnrichment

Updated: 2026-06-01T22:59:39.404Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-01T22:16:22.927

Modified: 2026-06-02T13:04:00.123

Link: CVE-2026-0094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T02:30:16Z

Weaknesses