Local Privilege Escalation Vulnerability in Android by Google
CVE-2026-0063
10CRITICAL
What is CVE-2026-0063?
A logic error in the PhoneInterfaceManager's setAllowedCarriers function creates a vulnerability that allows local privilege escalation. This security gap enables unauthorized users to circumvent carrier restrictions without requiring additional execution permissions or user interaction. Addressing this flaw is essential for maintaining the integrity and security of the Android operating system.
Affected Version(s)
Android 17