CVE-2026-58744
massLocal Privilege Escalation via Improper Input Validation in Google Android
CVE-2026-58744 is a local privilege escalation flaw caused by improper input validation (CWE-20) in multiple locations of a Google component, disclosed through Google's device security CNA and phrased identically to standard Android Security Bulletin entries. An attacker who already runs code with low local privileges on the device — for example an already-installed unprivileged app or a local process — sends malformed input to the affected component to escalate privileges, requiring no user interaction and no additional execution privileges. Successful exploitation gives a high-impact compromise of confidentiality, integrity, and availability on the device (CVSS 3.1: 7.8), effectively allowing takeover of the affected device context. The source data does not name the specific component or affected version ranges, so defenders should consult the matching Android Security Bulletin to identify the fixed security patch level. No public proof of concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the Android security patch level that remediates this issue as soon as your OEM or carrier ships it, and verify the level under Settings > About phone > Android security patch level. Because exploitation is local and needs no user interaction, restrict sideloading and untrusted app installation until devices are patched. Review the relevant Android Security Bulletin entry once published to confirm the component list and any additional mitigations.
| Google Android (specific component not identified in the advisory) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.