VYPR
High severity7.8NVD Advisory· Published Jun 1, 2026· Updated Jun 1, 2026

CVE-2026-0096

CVE-2026-0096

Description

A UI issue in Android's ForgetDeviceDialogFragment allows privilege escalation by tricking users into forgetting devices without interaction.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A UI issue in Android's ForgetDeviceDialogFragment allows privilege escalation by tricking users into forgetting devices without interaction.

Vulnerability

A flaw exists in the getAppLabel function within ForgetDeviceDialogFragment.java in Android. This vulnerability allows for a potential privilege escalation by misleading the user through insufficient UI prompts when forgetting a device. The exact affected versions are not specified in the available references, but it is addressed in the June 2026 Android Security Bulletin [1].

Exploitation

Exploitation does not require user interaction. An attacker can leverage the misleading or insufficient UI presented by the ForgetDeviceDialogFragment to trick a user into performing an action that results in privilege escalation. The vulnerability is local, meaning no additional execution privileges are needed beyond what the attacker already possesses to trigger the UI.

Impact

Successful exploitation of this vulnerability could lead to a local privilege escalation. The attacker gains higher privileges on the device without needing any additional execution capabilities. The specific scope and nature of the escalated privileges are not detailed in the provided references.

Mitigation

This vulnerability is addressed in the June 2026 Android Security Bulletin [1]. Users should ensure their Android devices are updated to receive the security patch. No specific workarounds are mentioned in the available references, and the End-of-Life (EOL) status or Known Exploited Vulnerabilities (KEV) listing for this issue is not disclosed.

AI Insight generated on Jun 1, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.