NFC Spoofing Vulnerability in Android Products
CVE-2026-0081

10CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-0081?

A vulnerability in the NFC functionality of Android products allows an attacker to spoof an NFC event due to the absence of a required permission check. This weakness can lead to local escalation of privileges, enabling unauthorized actions without any user interaction. Immediate attention and remediation are recommended to protect sensitive data and system integrity.

Affected Version(s)

Android 17

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.