ZeroHour

CVE-2026-28659

niche

Local Privilege Escalation in Android MicroXR Blobstore via Missing Permission Check

CVSS 4.0
10.0 critical
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-28659 is a missing permission check (CWE-269, improper privilege management) in the MicroXR Blobstore component of the Android platform, assigned by Google's Android security team ([email protected]). A local attacker who can already run code on the affected device can trigger the flaw with no user interaction and no additional execution privileges, gaining access to other apps' files and escalating privileges locally. The issue is rated critical at CVSS 4.0 10.0 in the CVE record, although the described trigger is local code on the device rather than a remote attack. Affected are Android-based devices carrying the MicroXR Blobstore component; the CVE record itself does not list affected version ranges, so defenders must consult the corresponding Android security bulletin for affected and patched patch levels. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.2% probability of exploitation within 30 days (10th percentile).

What to do: Check the Android Security Bulletin entry for CVE-2026-28659 to identify the affected components and patched patch levels, and apply the corresponding OTA/system update on any Android XR devices in your estate as soon as it is available. Until patched, treat app-to-app file isolation on these devices as reduced and avoid installing untrusted apps on affected devices, since exploitation requires local code execution. No workaround is documented; with no public PoC and a 0.2% EPSS score, there is currently no indication of active exploitation.

Affected
Google (Android) MicroXR Blobstore (Android component)
Estimated exposure
nicheunknown; likely at most tens of thousands of devices (early-stage Android XR installed base) — MicroXR is part of Google's Android XR stack and the CVE is assigned by the Android CNA, so the plausible footprint is the small, recently launched Android XR device ecosystem rather than the multi-billion-unit Android phone and tablet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android xr
Weakness
CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.