Cross-User Permission Bypass in Android App Due to Misconfiguration
CVE-2026-0021
8.4HIGH
What is CVE-2026-0021?
A vulnerability in the hasInteractAcrossUsersFullPermission function within AppInfoBase.java exposes a potential cross-user permission bypass. This issue stems from a confused deputy problem, allowing a local escalation of privilege without requiring additional execution privileges. There is no need for user interaction to exploit this vulnerability, making it particularly concerning for app security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Android 16-qpr2
Android 16
Android 15