216.73.216.233

CVE-2026-0072

· Published 01/06/2026 19:16 · Modified 02/06/2026 13:04

Labels: CVE-2026-0072 2026-06-01CVE-2026-0072CWE-285[email protected]

Essential information

Published
01/06/2026 19:16
Modified
02/06/2026 13:04
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
android / android cpe:2.3:a:android:android:*:*:*:*:*:*:*:*

References