CVE-2026-28620
massLocal Privilege Escalation in Android via URI Permissions Bypass
CVE-2026-28620 is an incorrect-authorization flaw (CWE-863) in Android: in multiple code locations, a permissions bypass allows access to URIs that should be permission-protected. A local app with only ordinary, low-level privileges can trigger the flaw, and no user interaction is required, so any malicious or compromised app on the device can exploit it without extra permissions being granted. Successful exploitation results in local escalation of privilege, with high impact on the confidentiality, integrity, and availability of the affected device per the CVSS score of 7.8. Any unpatched Android device running the affected components is exposed, though the attacker must already have some code running locally on the device. There is no evidence of exploitation so far: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days.
What to do: Apply the Android security update that addresses CVE-2026-28620 as soon as it becomes available over-the-air, and check the Android Security Bulletin for the exact affected component and minimum patch level. Because exploitation requires a local app, defer installing untrusted or sideloaded apps on unpatched devices. Enterprise administrators should use MDM to inventory fleet security patch levels and confirm affected devices receive the OTA update.
| Google Android (AOSP/Android OS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.