CVE-2026-58724
massRace-Condition Use-After-Free in Google Android Enables Local Privilege Escalation
CVE-2026-58724 is a use-after-free vulnerability caused by a race condition that exists in multiple locations of Google's Android platform, as assigned by Google's Android vulnerability management CNA. A local attacker who already holds System execution privileges on a device can exploit the timing flaw to free and reuse memory, escalating their privileges beyond their current boundary; no user interaction is required. Successful exploitation results in local elevation of privilege with high impact on confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 7.0. The requirement for pre-existing privileges and a reliably won race (AV:L/AC:H) makes this primarily a defense-in-depth weakness rather than a remote attack vector. No public proof of concept is known, the issue is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Check the relevant Android Security Bulletin for the affected component and apply the vendor OTA update (security patch level) as soon as it ships for your devices. Because exploitation requires local access with pre-existing System execution privileges and winning a race condition, risk is contained; disabling installation of untrusted/third-party apps and enforcing managed-device policies further reduces exposure. Enterprise fleets should prioritize this patch on devices that run untrusted applications or are shared across users.
| Google Android | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.