CVE-2026-57012
Google · Android
A missing permission check in the Android Setup Wizard allows for unauthenticated remote package installation and privilege escalation without requiring user interaction.
Executive summary
A high-severity privilege escalation vulnerability in the Android Setup Wizard allows unauthenticated attackers to remotely install malicious packages.
Vulnerability
The vulnerability stems from a missing permission check within the Setup Wizard component. This flaw permits an unauthenticated attacker to perform remote package installations, effectively escalating privileges on the device without requiring user intervention.
Business impact
The ability for an unauthorized party to remotely install packages on an Android device poses a severe threat to data confidentiality, integrity, and availability. With a CVSS score of 8.4, this vulnerability could facilitate the deployment of persistent malware, unauthorized data exfiltration, or complete device compromise, leading to significant reputational damage and potential loss of sensitive user information.
Remediation
Immediate Action: Users and administrators should apply the latest security updates provided by Google or the specific device manufacturer as soon as they become available.
Proactive Monitoring: Security teams should monitor device logs for unexpected package installation events or anomalous activity originating from the Setup Wizard process.
Compensating Controls: Ensure that enterprise mobile device management (MDM) policies restrict the installation of apps from unknown sources and enforce regular security patch cycles across the fleet.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high impact of remote privilege escalation and the lack of user interaction required for exploitation, this vulnerability represents a significant security risk. Organizations should prioritize updating all managed Android devices to the most recent security patch level to mitigate the possibility of remote package injection and unauthorized system access.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.4 (3.1)
- Analyst report written