Tapjacking Vulnerability in Android's WindowState.java
CVE-2026-0061

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0061?

A vulnerability in the functions of WindowState.java allows attackers to manipulate the user interface through a tapjacking or overlay attack. This exploit may enable local escalation of privileges without requiring any interaction from the user, presenting a significant security risk. Attackers can potentially deceive users into granting permissions erroneously, exposing sensitive information or system resources. Organizations using affected versions of Android OS should adopt immediate measures to mitigate this risk.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.