Information Disclosure Vulnerability in Contacts Provider for Android
CVE-2026-0057

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-0057?

The Contacts Provider component in Android contains a vulnerability that allows unauthorized access to incoming call phone numbers and related metadata due to a missing permission check. This flaw enables local information disclosure without requiring any additional execution privileges or user interaction, posing a potential privacy risk to users. To mitigate this issue, it's essential for users to stay informed about updates and apply security patches promptly.

Affected Version(s)

Android 17

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.