CVE-2026-28659
nicheLocal Privilege Escalation in Android MicroXR Blobstore via Missing Permission Check
CVE-2026-28659 is a missing permission check (CWE-269, improper privilege management) in the MicroXR Blobstore component of the Android platform, assigned by Google's Android security team ([email protected]). A local attacker who can already run code on the affected device can trigger the flaw with no user interaction and no additional execution privileges, gaining access to other apps' files and escalating privileges locally. The issue is rated critical at CVSS 4.0 10.0 in the CVE record, although the described trigger is local code on the device rather than a remote attack. Affected are Android-based devices carrying the MicroXR Blobstore component; the CVE record itself does not list affected version ranges, so defenders must consult the corresponding Android security bulletin for affected and patched patch levels. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile).
What to do: Check the Android Security Bulletin entry for CVE-2026-28659 to identify the affected components and patched patch levels, and apply the corresponding OTA/system update on any Android XR devices in your estate as soon as it is available. Until patched, treat app-to-app file isolation on these devices as reduced and avoid installing untrusted apps on affected devices, since exploitation requires local code execution. No workaround is documented; with no public PoC and a 0.2% EPSS score, there is currently no indication of active exploitation.
| Google (Android) MicroXR Blobstore (Android component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android xr
- Weakness
- CWE-269
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.