AntiMalware•August 20, 2026•🇷🇺Translated from Russian

PoC Exploit Released for Android CVE-2026-0075 Allowing Contact Theft Without READ_CONTACTS Permission

A researcher has published a proof-of-concept exploit for vulnerability CVE-2026-0075 in Android. The flaw resided in the system component ContactsProvider2 and allowed a local application to reach the contacts database via SQL injection even when the user had never granted the READ_CONTACTS permission.

No additional user interaction or confirmation dialogs were required. The vulnerability stemmed from overly verbose SQLite error messages returned by ContactsProvider2 when specially crafted queries triggered database errors. By analyzing these responses, an application without any contact permissions could gradually reconstruct entries from the contacts database.

Google assigned the issue a high severity rating. It affects Android 14, Android 15, Android 16 and Android 16 QPR2, according to the June 2026 Android security bulletin. The official patch removes detailed JSON error information from responses sent to applications lacking contact access rights, replacing it with a generic message.

The PoC exploit published on GitHub intentionally does not request READ_CONTACTS or WRITE_CONTACTS permissions. Its author designed it for controlled laboratory testing to compare the behavior of patched and vulnerable builds. The researcher notes that a successful test on one device does not prove the vulnerability exists on every smartphone running the same Android version.

No confirmed cases of real-world exploitation of CVE-2026-0075 have been observed so far. However, the availability of public exploit code makes it unrealistic to expect older, unpatched firmware to remain safe. Users should check their device security update level in settings and ensure installation of the patch dated 5 June 2026 or newer.

Related articles

Security NEXT•Vulnerabilities & Exploits

Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks

Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.

Security NEXT•Vulnerabilities & Exploits

Apple Releases iOS 26.7.1 and iPadOS 26.7.1 to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted Attacks

Apple has issued iOS 26.7.1 and iPadOS 26.7.1 to address a high-severity vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when processing a specially crafted file due to an out-of-bounds write. The company stated that the issue may have been exploited in sophisticated, targeted attacks against specific individuals on versions prior to iOS 27. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. On the same day, Apple also released iOS 27.0.1 and iPadOS 27.0.1, though those updates did not reference CVE-2026-86950. The patches close a vector that could be abused for remote code execution in image rendering components.

Habr•Vulnerabilities & Exploits

Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS

Researchers from Graz University of Technology demonstrated how built-in file change notification mechanisms can leak sensitive user activity without requiring elevated privileges. The affected subsystems include inotify on Linux, FileObserver on Android, ReadDirectoryChangesW on Windows, and FSEvents on macOS. On Linux the technique enables reconstruction of typed text with 93-100% accuracy by monitoring /dev/input/event4 timestamps. Android apps can break sandbox isolation to observe messaging events, while Windows monitoring of browser cache files reveals visited websites at 97.8% accuracy. Only partial mitigations have been deployed in Linux and Windows, with no fixes available for Android or macOS. Additional attacks remain possible, including detection of password prompts to facilitate phishing overlays.

AntiMalware•Vulnerabilities & Exploits

16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform

A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.