cbcvebase.
CVE-2026-0005
published 2026-03-02

CVE-2026-0005: In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps…

medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

10 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformframeworks_base>= 14:0 < 14:2026-03-0114:2026-03-01
platformframeworks_base>= 15:0 < 15:2026-03-0115:2026-03-01
platformframeworks_base>= 16-qpr2-next:0 < 16-qpr2-next:2026-03-0116-qpr2-next:2026-03-01
platformframeworks_base>= 16:0 < 16:2026-03-0116:2026-03-01