{"api_version":"1","generated_at":"2026-06-02T03:15:46+00:00","cve":"CVE-2026-0094","urls":{"html":"https://cve.report/CVE-2026-0094","api":"https://cve.report/api/cve/CVE-2026-0094.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0094","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0094"},"summary":{"title":"CVE-2026-0094","description":"In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","state":"PUBLISHED","assigner":"google_android","published_at":"2026-06-01 22:16:22","updated_at":"2026-06-01 23:16:17"},"problem_types":["CWE-451","Elevation of privilege","CWE-451 CWE-451 User Interface (UI) Misrepresentation of Critical Information"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-06-01","name":"https://source.android.com/docs/security/bulletin/2026/2026-06-01","refsource":"security@android.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0094","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0094","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Google","product":"Android","version":"affected 16-qpr2","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 16","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 15","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 14","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-0094","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-06-01T22:59:23.602490Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-451","description":"CWE-451 User Interface (UI) Misrepresentation of Critical Information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T22:59:47.636Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Android","vendor":"Google","versions":[{"status":"affected","version":"16-qpr2"},{"status":"affected","version":"16"},{"status":"affected","version":"15"},{"status":"affected","version":"14"}]}],"descriptions":[{"lang":"en","value":"In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."}],"problemTypes":[{"descriptions":[{"description":"Elevation of privilege","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T21:14:55.139Z","orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android"},"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-06-01"}],"x_generator":{"engine":"cvelib 1.7.1"}}},"cveMetadata":{"assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","assignerShortName":"google_android","cveId":"CVE-2026-0094","datePublished":"2026-06-01T21:14:55.139Z","dateReserved":"2025-10-15T15:42:54.883Z","dateUpdated":"2026-06-01T22:59:47.636Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-01 22:16:22","lastModifiedDate":"2026-06-01 23:16:17","problem_types":["CWE-451","Elevation of privilege","CWE-451 CWE-451 User Interface (UI) Misrepresentation of Critical Information"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"94","Ordinal":"1","Title":"CVE-2026-0094","CVE":"CVE-2026-0094","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"94","Ordinal":"1","NoteData":"In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","Type":"Description","Title":"CVE-2026-0094"}]}}}