Android Contacts Database SQL Injection Vulnerability Allowing Privilege Escalation

Vulnerability

A SQL injection vulnerability has been identified in multiple functions within the Android framework. This issue allows unauthorized access to the contacts database, potentially leading to local privilege escalation. The vulnerability does not require any additional execution privileges or user interaction for exploitation. It affects devices running Android versions 14, 15, 16, and 16-qpr2.

Impact

Exploitation of this vulnerability could result in unauthorized access to the contacts database, allowing for local privilege escalation on the affected device.

Remediation

Users can update their devices to the June 2026 security patch level to address this vulnerability. Instructions for checking and updating the Android version are available on the Google Support website.

Added: Jun 1, 2026, 10:42 PM
Updated: Jun 1, 2026, 10:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.