CVE-2026-0007

8.6

Google · Android

A tapjacking or overlay vulnerability in the WindowInfo component of Android allows for local escalation of privilege.

Executive summary

A critical local privilege escalation vulnerability exists in Google Android versions 14, 15, and 16, which could allow an attacker to bypass permission controls via a tapjacking attack.

Vulnerability

This flaw involves a tapjacking or overlay attack within the WindowInfo.cpp component, enabling an attacker to trick a user into granting permissions. The vulnerability allows for local escalation of privilege without requiring prior execution privileges or specific user interaction.

Business impact

The ability for a local attacker to escalate privileges represents a significant compromise of the Android security model. Successful exploitation could lead to unauthorized access to sensitive application data, system-level control, and the potential for persistent malware installation, justifying the high CVSS score of 8.6.

Remediation

Immediate Action: Apply the official security updates provided in the March 2026 Android Security Bulletin as soon as they are available for your specific device.

Proactive Monitoring: Monitor device logs for unusual overlay activity or unexpected permission requests that occur without explicit user initiation.

Compensating Controls: Maintain system integrity by avoiding the installation of applications from untrusted third party sources, which are the primary delivery vectors for overlay attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, particularly for enterprise environments managing mobile fleets. Administrators must prioritize the deployment of the March 2026 security patches to all managed handsets to prevent potential privilege escalation and subsequent device compromise.

More Google CVEs

Sources