CVE-2026-28656
Google · Android
A tapjacking vulnerability in DeviceAdminAdd.java allows local escalation of privilege on Android devices, requiring user interaction to execute.
Executive summary
A high-severity local privilege escalation vulnerability in Google Android allows attackers to perform tapjacking attacks that could lead to unauthorized system control.
Vulnerability
The vulnerability resides in multiple functions within DeviceAdminAdd.java, where a failure to properly handle overlays permits a tapjacking attack. Exploitation requires a local attacker with low privileges to trick a user into interacting with a malicious overlay.
Business impact
Successful exploitation of this flaw allows a local, low-privileged attacker to achieve elevated privileges on an affected Android device. With a CVSS score of 7.3, this represents a significant risk to data confidentiality, integrity, and availability, as the attacker could gain unauthorized control over device administration functions.
Remediation
Immediate Action: Users and administrators should apply the latest security updates provided by Google as soon as they become available for their specific device model.
Proactive Monitoring: Security teams should monitor device logs for suspicious overlay activity or unexpected changes to device administrator permissions.
Compensating Controls: Users should exercise caution when granting administrative permissions to applications and avoid installing software from untrusted sources, which serves to limit the potential for malicious overlays to be deployed.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for local privilege escalation, this vulnerability poses a clear risk to device integrity. Organizations should prioritize the deployment of the forthcoming security patches once released by Google to ensure that the vulnerable components in the Android OS are remediated.
More Google CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.3 (3.1)
- Analyst report written