SQL Injection Vulnerability in Android Products by Google
CVE-2026-0075

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0075?

A security vulnerability has been identified in multiple functions of Google Android products, allowing unauthorized access to the contacts database through SQL injection. This exploit does not require any user interaction or additional execution privileges, which raises serious concerns about data integrity and user privacy on affected Android devices.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.