Android Domain Verification Service Logic Error Vulnerability Allowing App Link Hijacking

Vulnerability

A logic error has been identified in the Domain Verification Service component of Android, specifically within the approvalLevelForDomainInternal function. This vulnerability creates a potential for hijacking arbitrary app links, leading to unauthorized escalation of privileges. Notably, exploitation of this issue does not require any additional execution privileges or user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized escalation of privileges, allowing a user to gain elevated rights or access within the application or system.

Remediation

Users can update their devices to the June 2026 security patch level to address this vulnerability. Instructions for checking and updating the Android version are available on the Google Support website.

Added: Jun 1, 2026, 10:37 PM
Updated: Jun 1, 2026, 10:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.3
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.