Plateforme
android
Composant
email-application
Corrigé dans
4.2.1
4.0.1
3.1.1
2.0.1
14.2.1
14.0.1
13.0.1
12.0.1
CVE-2026-28548 describes an improper verification vulnerability within the Android Email Application. Successful exploitation could compromise the confidentiality of email data. This vulnerability impacts versions of the Email Application up to and including 14.2.0. A patch is expected to address this issue.
The improper verification flaw allows an attacker to potentially access sensitive email content. This could include personal communications, financial details, or other confidential information stored within the application. While the specific attack vector isn't detailed, the impact centers on unauthorized access to data. The confidentiality of email services is at risk, potentially leading to identity theft, financial fraud, or exposure of sensitive business information. The blast radius extends to any user utilizing the vulnerable version of the Email Application.
CVE-2026-28548 was publicly disclosed on 2026-03-05. The vulnerability's severity is rated HIGH (CVSS 7.1). There are currently no publicly available proof-of-concept exploits. The vulnerability is not listed on the CISA KEV catalog as of this writing.
Users of Android devices running the Email Application, particularly those with older devices or those who haven't enabled automatic updates, are at risk. Individuals who frequently handle sensitive information via email are especially vulnerable.
disclosure
Statut de l'Exploit
EPSS
0.01% (percentile 0%)
CISA SSVC
Vecteur CVSS
The primary mitigation for CVE-2026-28548 is to upgrade to a patched version of the Android Email Application. Since a specific fixed version isn't provided, users should monitor for updates released by Google. As a temporary workaround, users could consider disabling automatic email syncing or limiting the amount of sensitive information stored within the application until a patch is available. Regularly review app permissions to ensure only necessary access is granted.
Actualice la aplicación de correo electrónico a la última versión disponible proporcionada por Huawei para HarmonyOS. Esto solucionará la vulnerabilidad de verificación incorrecta y protegerá la confidencialidad del servicio.
Analyses de vulnérabilités et alertes critiques directement dans votre boîte mail.
CVE-2026-28548 is a HIGH severity vulnerability affecting the Android Email Application versions up to 14.2.0. It involves improper verification, potentially leading to data confidentiality breaches.
If you are using the Android Email Application version 14.2.0 or earlier, you are potentially affected by this vulnerability. Check your app version and update if a patch is available.
The recommended fix is to upgrade to a patched version of the Android Email Application. Monitor for updates released by Google.
As of now, there are no publicly known active exploitation campaigns targeting CVE-2026-28548.
Refer to the official Android Security Bulletins and Google's security pages for updates and advisories related to CVE-2026-28548.
Téléverse ton fichier de dépendances et découvre instantanément si cette CVE et d'autres te touchent.
Téléverse ton fichier build.gradle et nous te dirons instantanément si tu es affecté.