CVE-2026-58691
Google · Android
A permission bypass vulnerability in the Android kernel function FsmReleaseKey allows for local escalation of privilege without requiring user interaction or elevated execution privileges.
Executive summary
A high-severity local privilege escalation vulnerability in the Android kernel enables unauthorized users to gain elevated system permissions without interaction.
Vulnerability
The vulnerability exists within the FsmReleaseKey function in fsm.c due to improper input validation, which permits an unauthenticated local attacker to bypass existing permission checks and achieve full system control.
Business impact
The potential for local escalation of privilege poses a severe threat to data confidentiality, integrity, and availability. Successful exploitation allows an attacker to bypass security boundaries, potentially leading to unauthorized data access, the installation of persistent malicious code, and total compromise of the affected device. With a CVSS score of 8.4, this vulnerability is categorized as high severity and requires immediate attention to protect enterprise mobile assets.
Remediation
Immediate Action: Apply the latest security updates provided by Google or the specific device manufacturer as soon as they become available to patch the Android kernel.
Proactive Monitoring: Review system logs for signs of anomalous process behavior or unauthorized attempts to access protected kernel-level functions.
Compensating Controls: Ensure that device management policies restrict the installation of untrusted applications and maintain strict control over physical and logical access to enterprise mobile devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise via privilege escalation, administrators should prioritize the deployment of the next available Android security bulletin patch. Until the patch is applied, limit the exposure of mobile devices to untrusted environments and monitor for suspicious local activity that may indicate an attempt to leverage kernel-level flaws.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.4 (3.1)
- Analyst report written