ZeroHour

CVE-2026-58724

mass

Race-Condition Use-After-Free in Google Android Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-58724 is a use-after-free vulnerability caused by a race condition that exists in multiple locations of Google's Android platform, as assigned by Google's Android vulnerability management CNA. A local attacker who already holds System execution privileges on a device can exploit the timing flaw to free and reuse memory, escalating their privileges beyond their current boundary; no user interaction is required. Successful exploitation results in local elevation of privilege with high impact on confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 7.0. The requirement for pre-existing privileges and a reliably won race (AV:L/AC:H) makes this primarily a defense-in-depth weakness rather than a remote attack vector. No public proof of concept is known, the issue is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

What to do: Check the relevant Android Security Bulletin for the affected component and apply the vendor OTA update (security patch level) as soon as it ships for your devices. Because exploitation requires local access with pre-existing System execution privileges and winning a race condition, risk is contained; disabling installation of untrusted/third-party apps and enforcing managed-device policies further reduces exposure. Enterprise fleets should prioritize this patch on devices that run untrusted applications or are shared across users.

Affected
Google Android
Estimated exposure
massPotentially on the order of hundreds of millions of Android devices (10^8), pending version scoping — Google reports 3+ billion monthly active Android devices and the vulnerable code ships in the base OS, but the advisory does not specify which versions or builds are affected, so the count cannot be scoped more precisely.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.