ZeroHour

CVE-2026-28604

mass

Use-after-free race condition enables remote code execution in Android

CVSS 3.1
7.5 high
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-28604 is a use-after-free vulnerability in Android, present 'in multiple locations,' where a race condition allows memory to be freed while still in use. Because it is reachable with no additional execution privileges and requires no user interaction, a remote attacker can trigger the race and gain remote code execution on the affected device. The flaw was addressed in the September 2026 Android Security Update, which Google describes as fixing critical RCE-enabling bugs. Any Android device running a still-affected version that has not yet received that update is potentially exposed, though the bulletin data does not identify the specific component or version range. There is no evidence of exploitation so far: no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2%.

What to do: Apply the September 2026 Android security update via OTA as soon as it is offered for your devices, and verify the installed security patch level through device settings or an MDM inventory. Because exploitation requires no user interaction or privileges, prioritize fleet-wide patch verification rather than waiting on user reports. Watch the Android Security Bulletin for follow-up detail on the affected component and version ranges as scoring and technical details are finalized.

Affected
Google (Android) Android OS
Estimated exposure
masspotentially on the order of 1-3 billion Android devices, limited to those awaiting the September 2026 patch — Android runs on roughly 3 billion+ active devices worldwide and monthly security bulletins apply across the supported release line, so a flaw fixed in the platform-level September 2026 update plausibly touches a very large share of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.