CVE-2026-28659

10.0

Google · Android XR

A missing permission check in the MicroXR Blobstore allows unauthenticated attackers to access files belonging to other applications, resulting in local escalation of privilege.

Executive summary

A critical vulnerability in Google Android XR version 14 allows unauthenticated local escalation of privilege due to improper access control in the MicroXR Blobstore.

Vulnerability

The vulnerability exists within the MicroXR Blobstore component due to a missing permission check, which permits unauthorized access to sensitive application files. The vulnerability can be triggered by an unauthenticated attacker without requiring user interaction.

Business impact

The ability for an unauthorized entity to access files from other applications poses a severe risk to data confidentiality and integrity. Given the CVSS score of 10.0, this flaw effectively bypasses the security boundary of the Android sandbox, potentially exposing user credentials, private data, or system configuration files to compromise.

Remediation

Immediate Action: Organizations must monitor the official Google Android security bulletin for the release of a security patch and apply it to all affected Android XR devices as soon as it becomes available.

Proactive Monitoring: Security teams should review device access logs for unusual patterns of file system interaction or unexpected attempts to access protected application directories by unauthorized processes.

Compensating Controls: While standard mobile environments offer limited traditional WAF protection, ensure that mobile device management (MDM) policies are strictly enforced to restrict the installation of untrusted or unauthorized applications that could act as a vector for this vulnerability.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a critical security failure in the Android XR platform that requires immediate attention. Organizations should prioritize patching as soon as the vendor releases the fix, as the combination of unauthenticated access and high privilege escalation potential creates an extreme risk to the entire device ecosystem.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources