{"id":"ASB-A-471127462", "published":"2026-06-01T00:00:00Z", "modified":"2026-06-25T15:18:14.132838247Z", "aliases":["CVE-2026-0088", "A-471127462"], "details":"In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/packages/apps/CertInstaller", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"17-next:0"}, {"fixed":"17-next:2026-06-01"}]}], "versions":["17-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/0034ca47f9c3552e0f2d5e361f210eb92e6db805"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["319412844134037140839998539951349491557", "141099737433831504269937223695128924636", "179766561209369088213952349684202087401", "122575806031641559561753320778741501913"], "threshold":0.9}, "id":"ASB-A-471127462-91838fcc", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/0034ca47f9c3552e0f2d5e361f210eb92e6db805", "target":{"file":"src/com/android/certinstaller/CertInstaller.java"}}]}}, {"package":{"name":"platform/packages/apps/CertInstaller", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"15:0"}, {"fixed":"15:2026-06-01"}]}], "versions":["15"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/41228b5ffcfc45257a37fe818aa54ae8c5004b3b"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["319412844134037140839998539951349491557", "141099737433831504269937223695128924636", "179766561209369088213952349684202087401", "122575806031641559561753320778741501913"], "threshold":0.9}, "id":"ASB-A-471127462-0abd7c68", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/41228b5ffcfc45257a37fe818aa54ae8c5004b3b", "target":{"file":"src/com/android/certinstaller/CertInstaller.java"}}]}}, {"package":{"name":"platform/packages/apps/CertInstaller", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16:0"}, {"fixed":"16:2026-06-01"}]}], "versions":["16"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/188975dcb8d48bf13b0c4edfd65f55e5d618cd19"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["319412844134037140839998539951349491557", "141099737433831504269937223695128924636", "179766561209369088213952349684202087401", "122575806031641559561753320778741501913"], "threshold":0.9}, "id":"ASB-A-471127462-c8b1fa62", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/188975dcb8d48bf13b0c4edfd65f55e5d618cd19", "target":{"file":"src/com/android/certinstaller/CertInstaller.java"}}]}}, {"package":{"name":"platform/packages/apps/CertInstaller", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16-qpr2:0"}, {"fixed":"16-qpr2:2026-06-01"}]}], "versions":["16-qpr2"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/21f346008305d857a4779eb98ee67e69fc7b0511"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["319412844134037140839998539951349491557", "141099737433831504269937223695128924636", "179766561209369088213952349684202087401", "122575806031641559561753320778741501913"], "threshold":0.9}, "id":"ASB-A-471127462-b077c764", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/21f346008305d857a4779eb98ee67e69fc7b0511", "target":{"file":"src/com/android/certinstaller/CertInstaller.java"}}]}}, {"package":{"name":"platform/packages/apps/CertInstaller", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14:0"}, {"fixed":"14:2026-06-01"}]}], "versions":["14"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/3dced430d0a90c017892ffeed3389c2592ff0378"], "severity":"High", "spl":"2026-06-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["319412844134037140839998539951349491557", "141099737433831504269937223695128924636", "179766561209369088213952349684202087401", "122575806031641559561753320778741501913"], "threshold":0.9}, "id":"ASB-A-471127462-e61ac025", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/3dced430d0a90c017892ffeed3389c2592ff0378", "target":{"file":"src/com/android/certinstaller/CertInstaller.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2026-06-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/c935d8d079131d200b11389bf01ab0ff8034ad00"}]}