Insecure Default Value Leads to Permission Issues in Android's NfcDispatcher
CVE-2026-0082

10CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-0082?

A security flaw in the NfcDispatcher component of Android may allow for automatic assignment of special app access permissions due to an insecure default configuration. This vulnerability can be exploited locally without requiring any additional execution privileges or user interaction, potentially enabling unauthorized users to gain elevated privileges on the affected device.

Affected Version(s)

Android 17

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.