Black & White Path
Aug 21, 2026 · Information Security
CVE-2026-0075: Android ContactsProvider SQL Side‑Channel Vulnerability Deep Dive and PoC
CVE-2026-0075 is a high‑severity local privilege escalation and data‑leak flaw in Android's ContactsProvider2 that lets an app without any contacts permissions infer address‑book contents via SQLite error messages, affecting Android 14‑16 and mitigated by June 2026 security patches.
AndroidCVE-2026-0075ContactsProvider
0 likes · 9 min read
