CVE-2026-28614
Google · Android
A confused deputy vulnerability exists in the SlicePermissionActivity component of Android, allowing for local privilege escalation without user interaction.
Executive summary
A high severity privilege escalation vulnerability in Google Android allows local attackers to gain elevated system permissions without user interaction.
Vulnerability
This vulnerability occurs in the onCreate method of SlicePermissionActivity.java, where a confused deputy flaw enables local attackers to bypass permission checks and escalate privileges.
Business impact
The ability for a local attacker to escalate privileges poses a significant risk to the integrity and confidentiality of the entire mobile device. With elevated access, an attacker could potentially bypass security controls, access sensitive user data, or install malicious applications. The CVSS score of 7.8 reflects the high potential for compromise, despite the requirement for local access.
Remediation
Immediate Action: Organizations and users must apply the security patches provided in the September 2026 Android Security Bulletin as soon as they are made available by the device manufacturer.
Proactive Monitoring: Security teams should monitor for unauthorized application behavior or unexpected privilege changes on managed mobile devices.
Compensating Controls: Ensure that enterprise mobile device management (MDM) policies are strictly enforced to restrict unauthorized application installations and limit the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity of this privilege escalation flaw, device administrators should prioritize the deployment of the latest security updates provided by Google and OEM partners. Failure to patch could allow local malicious actors to compromise the device security model, leading to unauthorized access to sensitive data and system functions.
More Google CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written