CVE-2026-28620
Google · Android
A permissions bypass in Google Android allows for unauthorized URI access, potentially leading to local escalation of privilege without user interaction.
Executive summary
A high-severity permissions bypass vulnerability in Google Android allows local attackers to escalate privileges without requiring user interaction.
Vulnerability
This vulnerability involves a permissions bypass that enables unauthorized URI access within the Android operating system. The flaw allows a local, low-privileged attacker to achieve full escalation of privilege without needing user interaction or additional execution permissions.
Business impact
Successful exploitation of this vulnerability could grant an attacker full control over the local device, leading to unauthorized access to sensitive user data, system configurations, and applications. Given the CVSS score of 7.8, the potential for local escalation of privilege presents a significant risk to organizational data integrity and device security, particularly in environments where mobile devices are used to access corporate resources.
Remediation
Immediate Action: Organizations should monitor the official Google Android security bulletin for the release of firmware updates and apply them to all managed devices immediately upon availability.
Proactive Monitoring: Security teams should monitor device logs for unusual process activities or unauthorized attempts to access system-level URIs that deviate from standard behavioral baselines.
Compensating Controls: Ensure that mobile device management policies are strictly enforced to limit the installation of untrusted applications, which reduces the likelihood of a malicious actor gaining the necessary local access to trigger this exploit.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant local security risk that could facilitate unauthorized privilege escalation. Administrators should prioritize the deployment of upcoming security patches as soon as they are provided by Google to ensure the continued integrity and security of the Android device fleet.
More Google CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written