ZeroHour

CVE-2026-58744

mass

Local Privilege Escalation via Improper Input Validation in Google Android

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-58744 is a local privilege escalation flaw caused by improper input validation (CWE-20) in multiple locations of a Google component, disclosed through Google's device security CNA and phrased identically to standard Android Security Bulletin entries. An attacker who already runs code with low local privileges on the device — for example an already-installed unprivileged app or a local process — sends malformed input to the affected component to escalate privileges, requiring no user interaction and no additional execution privileges. Successful exploitation gives a high-impact compromise of confidentiality, integrity, and availability on the device (CVSS 3.1: 7.8), effectively allowing takeover of the affected device context. The source data does not name the specific component or affected version ranges, so defenders should consult the matching Android Security Bulletin to identify the fixed security patch level. No public proof of concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Android security patch level that remediates this issue as soon as your OEM or carrier ships it, and verify the level under Settings > About phone > Android security patch level. Because exploitation is local and needs no user interaction, restrict sideloading and untrusted app installation until devices are patched. Review the relevant Android Security Bulletin entry once published to confirm the component list and any additional mitigations.

Affected
Google Android (specific component not identified in the advisory)
Estimated exposure
massUp to billions of devices (Android's 3B+ active-device install base; the true count is lower and unknown because affected versions are unspecified) — Google has publicly stated Android runs on more than 3 billion active devices, which caps the reach of any core-platform flaw, though the actually exposed population cannot be pinned down because the advisory omits version ranges.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.