VendorsGoogleandroid_xr14
Vulnerabilities

Google Android Extended Reality (XR) 14

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-28659
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
10.0EPSS 0.001
CVE-2026-0072
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
10.0EPSS 0.001