CVE-2026-0020
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0020 is a permissions bypass vulnerability in Android's ParsedPermissionUtils.java (parsePermissionGroup method) that allows a local attacker to bypass the permission consent dialog and obtain elevated permissions without user interaction. It affects Google Android versions 14.0, 15.0, and 16.0 (including QPR2 beta variants). The vulnerability was published on March 2, 2026, with a patch included in the Android Security Bulletin dated 2026-03-01. It carries a CVSS v3.1 base score of 8.4 (High) (Android Security Bulletin, Red Hat CVE).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), residing in the parsePermissionGroup function of ParsedPermissionUtils.java within the Android framework. An attacker can exploit this flaw locally to bypass the system's permission consent dialog — the mechanism that normally requires explicit user approval before an app is granted sensitive permissions. No additional execution privileges are required, and user interaction is not needed, making this a zero-interaction local privilege escalation. No public proof-of-concept code has been identified at this time (Android Security Bulletin).

Impact

Successful exploitation leads to local escalation of privilege, allowing an unprivileged application to silently acquire permissions it would not normally be granted. This can result in high confidentiality, integrity, and availability impact — for example, an app could gain access to sensitive data (contacts, location, camera), modify system state, or interfere with device operation, all without the device owner's knowledge or consent (Android Security Bulletin, Red Hat CVE).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.006% (0.000060), indicating a very low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys scanners have detection coverage for this CVE (detection IDs 610761 and 610766) (Android Security Bulletin).

Mitigation and workarounds

Google has released a patch addressing this vulnerability in the Android Security Bulletin for 2026-03-01, applicable to Android 14.0, 15.0, and 16.0 (including QPR2 beta versions). Users and administrators should apply the March 2026 security patch level (2026-03-01 or later) to all affected devices as soon as possible. OEM-specific updates (e.g., Samsung, Huawei) incorporating this patch have also been released. No configuration-based workaround is known; patching is the only remediation (Android Security Bulletin, CIS Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory covering multiple Android vulnerabilities in the March 2026 bulletin, including CVE-2026-0020, noting the potential for privilege escalation (CIS Advisory). The vulnerability received brief coverage on social platforms including Mastodon and Bluesky via The Hacker Wire. Samsung and Huawei both incorporated the patch into their respective February/May 2026 security updates. Community reaction has been measured, consistent with the absence of active exploitation or public PoC.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management