Logic Error in Domain Verification Service Allows App Link Hijacking for Android Devices
CVE-2026-0087

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0087?

A vulnerability exists within the DomainVerificationService of Android, where a logic error in the approval logic for app links can be exploited to hijack arbitrary app links. This flaw allows attackers to escalate privileges locally without requiring any additional execution privileges or user interaction. Proper permissions and validations are crucial to protecting applications against such risks.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.