CVE-2026-0082
published 2026-06-17CVE-2026-0082: In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could…
critical10CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCHSIHSAH
EPSS
0.17%
6.0th percentile
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
CVE-2026-0082: In tryStartActivity of NfcDispatcher
cvelistv5·2026-06-17·CVSS 10.0
CVE-2026-0082 [CRITICAL] CVE-2026-0082: In tryStartActivity of NfcDispatcher
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value.
ghsa_unreviewed·2026-06-17
CVE-2026-0082 [CRITICAL] CWE-453 In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value.
In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published