ZeroHour

CVE-2026-28616

mass

Confused-Deputy Flaw in Android Setup Wizard Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-28616 is a confused-deputy vulnerability (CWE-441) in the Setup Wizard component of Android, assigned by Google's Android security team ([email protected]). An attacker who already holds low-privilege access on the device can trigger the Setup Wizard into forcing a connection to an attacker-controlled network without any user interaction, and this can be leveraged into a local escalation of privilege. Successful exploitation carries high impact — confidential data disclosure, integrity compromise, and denial of service — without requiring any additional execution privileges beyond the initial local foothold. All Android devices shipping an affected Setup Wizard build are potentially exposed; the available data does not enumerate specific affected Android versions, so defenders should consult the Android Security Bulletin patch details for their device. No public proof of concept is known, the issue is absent from CISA's Known Exploited Vulnerabilities catalog, and EPSS currently rates the 30-day exploitation probability at roughly 0.1% (2nd percentile), so no in-the-wild exploitation is known at this time.

What to do: Patch via the Android monthly security update / OEM firmware that includes the fix for CVE-2026-28616, and verify the installed patch level in Settings > About phone > Android security update. No interim network mitigations are meaningful because the attack is local, but prioritizing updates on shared or multi-user devices reduces risk since the attacker needs low-privilege local access. No public exploit or in-the-wild abuse is known at this time.

Affected
Google (Android) Android — Setup Wizard component
Estimated exposure
mass≈3 billion+ active Android devices (Setup Wizard ships on essentially all Android handsets and tablets) — Google has publicly cited roughly 3 billion active Android devices and the Setup Wizard is part of the standard Android build, so the vulnerable component is plausibly present on billions of devices even though exploitation requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-441
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.