Local Escalation of Privilege in Android Input Method Manager Service
CVE-2026-0072

10CRITICAL

Key Information:

Vendor

Google

Vendor
CVE Published:
1 June 2026

What is CVE-2026-0072?

A security vulnerability exists in the Input Method Manager Service of Android due to a missing permission check in the addInputMethodListener method. This issue can allow attackers to escalate privileges locally without requiring any additional execution privileges or user interaction, potentially compromising the security of the device.

Affected Version(s)

Android XR 14

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shengxin Xia
.