securityonline.info 8/19/2026, 2:01:09 PM · external

Google patches Android ContactsProvider2 SQLi high severity bug

Google patches Android ContactsProvider2 SQLi high severity bug

THE report details four critical vulnerabilities detected today, including CVE-2026-33824, CVE-2026-59310, CVE-2026-55040, and CVE-2026-65400, affecting various services such as Microsoft and Apple. Additionally, it highlights CVE-2026-0075, an Android elevation of privilege vulnerability in the ContactsProvider2, which allows unauthorized access to the contacts database via SQL injection without user interaction.

Google has patched this vulnerability, categorizing it as high severity (CVSS 7.8) and advises users to update their devices to prevent exploitation. A public proof-of-concept is available for testing purposes.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline