CVE-2026-45520

Google · Android

A confused deputy vulnerability exists in BiometricsSettingsBase.java within Android, allowing for local privilege escalation without user interaction.

Executive summary

A high-severity authentication bypass vulnerability in Google Android could allow a local attacker to escalate privileges and gain unauthorized system control.

Vulnerability

This vulnerability occurs in the onAttach function of BiometricsSettingsBase.java, where a confused deputy flaw enables an attacker to bypass authentication mechanisms. The attack vector is local, requiring low privileges but no user interaction to achieve successful exploitation.

Business impact

The ability for a local user to escalate privileges represents a significant security risk, as it allows unauthorized access to sensitive data and system-level functions. Given the CVSS score of 7.8, this vulnerability is classified as high severity, posing a substantial threat to the integrity and confidentiality of the device. Successful exploitation could lead to full system compromise, undermining the security posture of the Android platform.

Remediation

Immediate Action: Organizations and users should monitor the official Google Android security bulletin for the release of security patches and apply them to all affected devices immediately upon availability.

Proactive Monitoring: Security teams should review device access logs for unauthorized attempts to modify system configurations or access restricted biometric settings.

Compensating Controls: Ensure that device-level security policies, such as strict application sandboxing and restricted shell access, are enforced to limit the potential impact of local privilege escalation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the potential for total system compromise, this vulnerability requires urgent attention. Administrators must prioritize the deployment of manufacturer-provided security updates as soon as they are released to neutralize the escalation of privilege risk.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources