Tapjacking Vulnerability in Android's WindowState.java
CVE-2026-0048

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0048?

A vulnerability exists in the WindowState.java file of the Android operating system, enabling a potential tapjacking or overlay attack. This flaw allows an attacker to manipulate the user interface, tricking users into approving unauthorized permissions without their knowledge. The exploitation of this vulnerability does not require any additional execution privileges or user interaction, which poses a significant risk to the security and privacy of affected devices, particularly in scenarios involving sensitive applications.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.