Logic Error in Domain Verification Service Allows App Link Hijacking for Android Devices
CVE-2026-0087

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0087?

A vulnerability exists within the DomainVerificationService of Android, where a logic error in the approval logic for app links can be exploited to hijack arbitrary app links. This flaw allows attackers to escalate privileges locally without requiring any additional execution privileges or user interaction. Proper permissions and validations are crucial to protecting applications against such risks.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.