Local Priv Escal on Android via DomainVerificationService Logic Error
CVE-2026-0087 Published on June 1, 2026

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD


Products Associated with CVE-2026-0087

Want to know whenever a new CVE is published for Google Android? stack.watch will email you.

 

Affected Versions

Google Android: