CVE-2026-58695

Google · Android

A missing bounds check in the phy_power.c file of the Android kernel allows for local privilege escalation to system level.

Executive summary

A vulnerability in the Android kernel allows a local attacker to escalate privileges to the system level, posing a significant risk to device integrity.

Vulnerability

This vulnerability occurs in the gmc_phy_lp3_exit_restore_registers function within phy_power.c due to a missing bounds check. An attacker who has already obtained low level access to the system can exploit this flaw to achieve local privilege escalation to system execution privileges without requiring user interaction.

Business impact

The ability to escalate privileges to the system level allows an attacker to bypass security controls, access sensitive user data, and gain persistent control over the device. With a CVSS score of 7.8, this high-severity vulnerability represents a substantial threat to organizational data security and device management integrity, as it provides a path for full system compromise.

Remediation

Immediate Action: Organizations should review the official Google Android security bulletin for September 2026 and apply all relevant kernel updates provided by the device manufacturer as soon as they become available.

Proactive Monitoring: Security teams should monitor system logs for unusual process activity or attempts to access restricted system files that might indicate an ongoing privilege escalation attempt.

Compensating Controls: Ensure that mobile device management policies are strictly enforced and that users are restricted from installing applications from untrusted sources, which serves as a primary barrier against the initial access required to trigger this local exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of this vulnerability, administrators should prioritize the deployment of the latest security patches once released by Google and OEMs. While this issue requires existing access to the device, the potential for full system compromise necessitates a proactive approach to patching and device hardening to mitigate the risk of lateral movement or data exfiltration.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources