CVE-2026-28664
massLocal Privilege Escalation in Android Runtime via File Tampering Logic Error
CVE-2026-28664 is a logic error in the WriteImageToDisk function of runtime_image.cc, a component of the Android Runtime (ART) maintained in the Android Open Source Project, that allows file tampering on the local system. A low-privileged local application or process can trigger the flaw with no additional execution privileges and without any user interaction. Successful exploitation yields a local escalation of privilege, with the CVSS scoring high impact on confidentiality, integrity, and availability of the target device. All Android devices running builds that include the vulnerable code are potentially affected; the source data does not specify an affected version range. There is currently no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Apply the Android security update that addresses CVE-2026-28664 as soon as it appears in the Android Security Bulletin, and install OEM firmware updates (patch level including this fix) when they reach affected devices. Until patched, limit installation of untrusted local apps, since exploitation requires only a low-privileged local process and no user interaction. Confirm your device's Android security patch level against the bulletin to verify the fix has been applied.
| Google Android (Android Runtime / ART, runtime_image.cc WriteImageToDisk) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.