CVE-2026-0072
A missing permission check in Android’s InputMethodManagerService allows a local attacker to gain higher privileges on the device. The flaw can be exploited without any user interaction and does not require additional execution rights.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Google Android XR 14 devices.
Real-world impact
An attacker who can run code on the device can elevate their privileges to system level, potentially taking full control of the device, accessing sensitive data, and installing malicious software.
Why this severity
The CVSS score of 10 reflects the flaw’s ability to provide complete local privilege escalation with no user interaction, making it a critical vulnerability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 1, 2026 · Jun 1, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- source.android.com/docs/security/bulletin/xr/2…vendor advisory