CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now. # CVE202628576 # Android # SQLInjection # Andro

CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now. # CVE202628576 # Android # SQLInjection # Android17 # ContactsProvider # MobileSecurity # InfoSec # DataLeak # ExploitPoC # Pixel https:// securityonline.info/cve-2026-2 8576-android-contacts-sqli/?utm_source=mastodon&utm_medium=jetpack_social

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now. # CVE202628576 # Android # SQLInjection # Andro

mastodon:infosec-exchangeother19d ago kagi ↗

CVE-2026-28576 (CVSS 10) is a SQL injection in the Android Contacts Provider. A public PoC dumps all contacts with no permissions. Patch Android 17 now. # CVE202628576 # Android # SQLInjection # Android17 # ContactsProvider # MobileSecurity # InfoSec # DataLeak # ExploitPoC # Pixel https:// securityonline.info/cve-2026-2 8576-android-contacts-sqli/?utm_source=mastodon&utm_medium=jetpack_social