CVE-2026-0054

Summary

In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

VendorProductVersion RangeStatus
GoogleAndroid16-qpr2affected
GoogleAndroid16affected
GoogleAndroid15affected
GoogleAndroid14affected

Weaknesses

  • Information disclosure

References