ZeroHour

CVE-2026-28590

mass

Improper Encryption Key Validation Enables Local Privilege Escalation in Android

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-28590 is a local privilege escalation flaw in Android caused by a logic error that results in improper validation of encryption keys in multiple places in the code. It is triggered by code already running locally on the device, with no need for special execution privileges and no user interaction, so any app or process with local code execution could potentially exploit it. An attacker who exploits it gains elevated privileges on the affected device, which is most valuable as one link in a chained attack alongside other flaws (the September 2026 Android bulletin also fixed separate remote code execution issues). Affected parties are users of Android devices that have not yet received the September 2026 Android security update; the specific affected version ranges were not detailed in the available data. There is no known public proof of concept, it is not listed in CISA's Known Exploited Vulnerabilities catalog, and its current probability of exploitation within 30 days is estimated at 0.1%.

What to do: Install the September 2026 Android security update as soon as your device or MDM fleet offers it, and verify the installed patch level under Settings > About phone > Android security patch level. Because this flaw is exploitable only with local code execution, prioritize patching devices likely to run untrusted apps, and treat it as high-value to chain with the RCE bugs fixed in the same bulletin. Defenders with managed fleets should confirm OEM rollout schedules, since patch delivery depends on device maker and carrier.

Affected
Google (Android) Android OS (multiple components; assigned by [email protected])
Estimated exposure
masson the order of billions of Android devices worldwide awaiting the September 2026 patch — Android runs on roughly 70% of the world's 3+ billion active smartphones, and monthly security bulletins apply across many OEM devices, though the precise affected components/versions are unspecified.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-347
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.