
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0021 is a confused deputy (CWE-441) vulnerability in Android's AppInfoBase.java that enables a cross-user permission bypass, leading to local escalation of privilege. The flaw exists in the hasInteractAcrossUsersFullPermission method and requires no additional execution privileges or user interaction to exploit. Affected versions include Android 14.0, 15.0, 16.0, and 16.0 QPR2 variants. It was published on March 2, 2026, with a patch included in the Android March 2026 security bulletin. The CVSS v3.1 base score is 8.4 (High) (Android Bulletin, Red Hat CVE).
The root cause is a confused deputy flaw (CWE-441) in the hasInteractAcrossUsersFullPermission method within AppInfoBase.java, part of the Android Settings framework. The method improperly validates permission checks when acting on behalf of another caller, allowing a local unprivileged process to leverage the system's elevated trust to bypass cross-user permission boundaries. The attack vector is local, requires no privileges, and no user interaction, making it exploitable by any app running on the device without special setup. No public proof-of-concept code has been identified at this time (Android Bulletin, Feedly).
Successful exploitation allows an unauthenticated local attacker to escalate privileges and gain unauthorized access across Android user profile boundaries, bypassing intended permission restrictions. This could enable a malicious app to access data belonging to other user profiles on the same device (e.g., work profiles or secondary users), with high confidentiality, integrity, and availability impact. The scope is limited to the affected device, but the cross-user nature of the bypass significantly increases the risk of sensitive data exposure in multi-user or managed device environments (Android Bulletin, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.006% (0.000060), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (detection IDs 610761 and 610766).
Google released a patch for this vulnerability in the Android Security Bulletin dated 2026-03-01, covering Android versions 14.0, 15.0, and 16.0 (including QPR2 variants). Users and administrators should apply the March 2026 Android security update (patch level 2026-03-01 or later) as soon as possible. Until patching is complete, restricting physical or local access to vulnerable devices and limiting the installation of untrusted applications can reduce exposure (Android Bulletin).
The vulnerability was noted in coverage of the broader March 2026 Android security update, which addressed 129 flaws (GBHackers). The Center for Internet Security (CIS) issued an advisory on multiple vulnerabilities in the March 2026 Android update (CIS Advisory). Social media mentions were observed from security-focused accounts on Mastodon and Bluesky shortly after disclosure, and Samsung's February 2026 update was noted as incorporating related patches (SammyFans). Community reaction was measured, consistent with a high-severity but non-actively-exploited local privilege escalation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."