{"id":"ASB-A-471127462","details":"In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-471127462","CVE-2026-0088"],"modified":"2026-06-23T15:45:40.410020820Z","published":"2026-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2026-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/c935d8d079131d200b11389bf01ab0ff8034ad00"}],"affected":[{"package":{"name":"platform/packages/apps/CertInstaller","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17-next:0"},{"fixed":"17-next:2026-06-01"}]}],"versions":["17-next"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"deprecated":false,"target":{"file":"src/com/android/certinstaller/CertInstaller.java"},"source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/0034ca47f9c3552e0f2d5e361f210eb92e6db805","signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["319412844134037140839998539951349491557","141099737433831504269937223695128924636","179766561209369088213952349684202087401","122575806031641559561753320778741501913"]},"signature_version":"v1","id":"ASB-A-471127462-91838fcc"}],"spl":"2026-06-01","fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/0034ca47f9c3552e0f2d5e361f210eb92e6db805"],"types":["EoP"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-471127462.json"}},{"package":{"name":"platform/packages/apps/CertInstaller","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2026-06-01"}]}],"versions":["15"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"deprecated":false,"target":{"file":"src/com/android/certinstaller/CertInstaller.java"},"source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/41228b5ffcfc45257a37fe818aa54ae8c5004b3b","signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["319412844134037140839998539951349491557","141099737433831504269937223695128924636","179766561209369088213952349684202087401","122575806031641559561753320778741501913"]},"signature_version":"v1","id":"ASB-A-471127462-0abd7c68"}],"spl":"2026-06-01","fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/41228b5ffcfc45257a37fe818aa54ae8c5004b3b"],"types":["EoP"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-471127462.json"}},{"package":{"name":"platform/packages/apps/CertInstaller","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16:0"},{"fixed":"16:2026-06-01"}]}],"versions":["16"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["319412844134037140839998539951349491557","141099737433831504269937223695128924636","179766561209369088213952349684202087401","122575806031641559561753320778741501913"]},"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/188975dcb8d48bf13b0c4edfd65f55e5d618cd19","deprecated":false,"target":{"file":"src/com/android/certinstaller/CertInstaller.java"},"signature_version":"v1","id":"ASB-A-471127462-c8b1fa62"}],"spl":"2026-06-01","fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/188975dcb8d48bf13b0c4edfd65f55e5d618cd19"],"types":["EoP"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-471127462.json"}},{"package":{"name":"platform/packages/apps/CertInstaller","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16-qpr2:0"},{"fixed":"16-qpr2:2026-06-01"}]}],"versions":["16-qpr2"],"ecosystem_specific":{"spl":"2026-06-01","vanir_signatures":[{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["319412844134037140839998539951349491557","141099737433831504269937223695128924636","179766561209369088213952349684202087401","122575806031641559561753320778741501913"]},"target":{"file":"src/com/android/certinstaller/CertInstaller.java"},"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/21f346008305d857a4779eb98ee67e69fc7b0511","signature_version":"v1","id":"ASB-A-471127462-b077c764"}],"severity":"High","types":["EoP"],"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/21f346008305d857a4779eb98ee67e69fc7b0511"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-471127462.json"}},{"package":{"name":"platform/packages/apps/CertInstaller","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2026-06-01"}]}],"versions":["14"],"ecosystem_specific":{"spl":"2026-06-01","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["319412844134037140839998539951349491557","141099737433831504269937223695128924636","179766561209369088213952349684202087401","122575806031641559561753320778741501913"]},"target":{"file":"src/com/android/certinstaller/CertInstaller.java"},"source":"https://android.googlesource.com/platform/packages/apps/CertInstaller/+/3dced430d0a90c017892ffeed3389c2592ff0378","deprecated":false,"signature_version":"v1","signature_type":"Line","id":"ASB-A-471127462-e61ac025"}],"severity":"High","types":["EoP"],"fixes":["https://android.googlesource.com/platform/packages/apps/CertInstaller/+/3dced430d0a90c017892ffeed3389c2592ff0378"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-471127462.json"}}],"schema_version":"1.7.5"}