Beveiligingsadvies

CVE-2026-0072

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-01 17:38:48
Laatst bijgewerkt 2026-06-01 19:14:42
Toegewezen door google_android
CVSS-score 10.0
Status PUBLISHED

Beschrijving

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.