Activity Start Restrictions Bypass in Shared.java of Android Products
CVE-2026-0098
7.8HIGH
What is CVE-2026-0098?
A flaw in the getCallingPackageName function within Shared.java allows an attacker to bypass activity start restrictions, facilitating local escalation of privileges without the requirement for additional execution rights or user interaction. This vulnerability poses a significant risk as it can be abused to perform unauthorized actions on the device, thereby compromising the overall security of the affected Android systems.
Affected Version(s)
Android 16-qpr2
Android 16
Android 15