
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0007 is a tapjacking/overlay vulnerability in Android's WindowInfo.cpp (writeToParcel function) that allows a malicious application to trick users into accepting permissions they did not intend to grant, leading to local escalation of privilege. It affects Google Android versions 14.0, 15.0, and 16.0. The vulnerability was published on March 2, 2026, with a patch released via the Android Security Bulletin on March 3, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), manifesting in the writeToParcel method of WindowInfo.cpp within the Android framework. An attacker can deploy a malicious overlay or tapjacking UI that obscures a legitimate permission dialog, causing the user's tap to be registered as consent for a permission the attacker controls. The attack vector is local, requires no elevated privileges, and while user interaction is technically required (the user must tap), the interaction is coerced through deception rather than informed consent. No public proof-of-concept code has been identified at this time (Android Security Bulletin, Feedly).
Successful exploitation results in local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS scope: Changed). An attacker who tricks a user into granting an unintended permission could gain access to sensitive device data, modify system state, or disrupt device functionality — all without requiring any pre-existing elevated privileges. The changed scope indicates that the impact extends beyond the attacker's initial privilege boundary, potentially affecting other components or data on the device (Android Security Bulletin).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of this report. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, Android Security Bulletin).
TYPE_APPLICATION_OVERLAY or similar window types) on affected Android 14.0, 15.0, or 16.0 devices.WindowInfo.cpp's writeToParcel, obscuring the true nature of the permission request.SYSTEM_ALERT_WINDOW or overlay permissions without a clear legitimate use case; apps that display unusual UI elements over system dialogs.logcat) showing unexpected window layer changes or overlay events coinciding with permission grant dialogs; entries from WindowManagerService indicating overlay windows from non-system apps during permission prompts.Google released a patch addressing CVE-2026-0007 in the Android Security Bulletin for March 2026 (patch level 2026-03-01), covering Android versions 14.0, 15.0, and 16.0. Device owners and administrators should apply the March 2026 Android security update as soon as it is available for their device. As a workaround, users should avoid installing applications from untrusted sources and review overlay permissions granted to installed apps (Settings > Apps > Special app access > Display over other apps). Enterprise administrators should consider enforcing policies that restrict overlay-capable applications on managed devices (Android Security Bulletin, CIS Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Google Android OS, including CVE-2026-0007, that could allow for privilege escalation (CIS Advisory). Samsung also addressed the vulnerability in its own security update cycle, as noted in Samsung Mobile Security updates (Samsung Security). General community reaction has been measured, consistent with the low EPSS score and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."