CVE-2026-0075

MEDIUM WAF: High
CVSS 5.9 Published: 2026-06-01
CWE-89

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
googleandroid14.0
googleandroid15.0
googleandroid16.0
googleandroid16.0
googleandroid16.0
googleandroid16.0

References

Back to CVE Database