
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0034 is a local privilege escalation vulnerability in Android's ManagedServices.java, specifically within the setPackageOrComponentEnabled function. Improper input validation causes a notification policy desynchronization that can be exploited by a local, unprivileged attacker to gain elevated privileges. Affected versions include Android 14.0, 15.0, 16.0, and 16.0 QPR2 beta variants. The vulnerability was published on March 2, 2026, with a patch included in the Android Security Bulletin dated 2026-03-01. It carries a CVSS v3.1 base score of 8.4 (High) (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-20 (Improper Input Validation) in the setPackageOrComponentEnabled method of ManagedServices.java, a component responsible for managing notification listeners and other system services on Android. By supplying maliciously crafted input, an attacker can cause a desynchronization of the notification policy state, which the system then processes with elevated trust, enabling privilege escalation. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it straightforward to exploit once local code execution is achieved (Android Security Bulletin). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a local unprivileged user to escalate their privileges on the affected Android device, potentially gaining high-impact access to confidentiality, integrity, and availability of the system (all rated High in the CVSS scoring). This could enable an attacker to access sensitive user data, install malicious applications with elevated permissions, or persistently compromise the device. The scope is limited to the affected device (unchanged scope), but the full triad of CIA impacts makes this a significant risk for any multi-user or enterprise-managed Android deployment (Android Security Bulletin, Red Hat CVE).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting (Feedly). The EPSS score is approximately 0.008% (0.000080), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released a patch addressing this vulnerability in the Android Security Bulletin dated 2026-03-01, covering Android versions 14.0, 15.0, 16.0, and 16.0 QPR2 beta variants. Users and administrators should apply the March 2026 security patch level (2026-03-01 or later) to all affected Android devices as soon as possible (Android Security Bulletin). As a defense-in-depth measure, enforce the principle of least privilege for local user accounts and monitor for unauthorized privilege escalation attempts on managed devices. Samsung devices received the fix as part of the March 2026 security patch (SammyFans), and Huawei/HarmonyOS devices received it in the June 2026 security update (Huawei Bulletin).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Google Android OS, including CVE-2026-0034, that could allow for privilege escalation (CIS Advisory). The vulnerability received routine coverage from vulnerability tracking platforms and security news aggregators, with no notable researcher commentary or significant social media discussion beyond standard CVE publication notices.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."