#ContactsProvider
Original text: "SQL Injection Still Exists, Even in Android: One Picked Contact, Every Contact (CVE-2026-28576)" — Mobile Hacking Lab. Code, tables and figures below are reproduced verbatim with attribution captions. #CVE #C
https://core-jmp.org/2026/09/cve-2026-28576-android-sql-injection-contacts/
SQL Injection Still Exists in Android: One Picked Contact, Every Contact (CVE-2026-28576)
A critical SQL injection vulnerability in Android 17's ContactsProvider allows apps using the system contact picker to exfiltrate all contacts on a device without any permissions. Exploiting Android's targetSdk-gated security patches reveals how legacy API levels inherit pre-fix behavior.
core-jmp.org
September 9, 2026 at 10:41 AM