ZeroHour

CVE-2026-28594

mass

Use-After-Free Local Privilege Escalation in Android

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-28594 is a use-after-free vulnerability in the Android platform, caused by a logic error in the code and present in multiple locations in the affected code. It can be triggered by a local attacker with low privileges already running code on the device, and user interaction is not required for exploitation. Successful exploitation enables local escalation of privilege, with CVSS 3.1 scoring high impact on confidentiality, integrity, and availability (7.8, High). All Android devices running affected, unpatched versions are potentially exposed; the specific affected version ranges are not enumerated in the available data and will be listed in Google's Android Security Bulletin. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Apply the Android security update for this flaw via over-the-air (OTA) updates as soon as it is offered by Google or the device OEM, and verify the current 'Android security patch level' under device settings. Because this is a local privilege escalation requiring existing code execution on the device, standard hardening (installing apps only from trusted sources, timely patching) limits risk. Enterprises should monitor the Android Security Bulletin and track OEM firmware releases for their managed device fleets.

Affected
Google (Android) Android OS/platform (AOSP)
Estimated exposure
mass≈billions of Android devices (Android's global active install base exceeds 3 billion) — Android's installed base is estimated at over 3 billion active devices, so any unpatched Android device on an affected version is plausibly affected, though exploitation requires the attacker to already execute code locally on the device.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-693
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.