Tapjacking Vulnerability in Letterbox.java of Android Products
CVE-2026-0046

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0046?

The vulnerability in Letterbox.java allows for a potential tapjacking attack, wherein an attacker may trick users into inadvertently accepting permissions through deceptive overlays. This exploit does not require additional execution privileges or user interaction, making it particularly concerning for users' security. Affected systems should update to latest security patches to mitigate this risk.

Affected Version(s)

Android 16

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.