Description
In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the CPM component, where a confused deputy allows an adversary with system execution privileges to read data it is not authorized to access. No user interaction is required, and the flaw can result in the disclosure of sensitive information that normally would be protected by privilege restrictions. This information leakage can compromise user data and compromise trust in the Android platform.

Affected Systems

Google Android devices running the Android operating system are affected. The CVE description does not specify particular Android OS releases, so any device with this vulnerability present may be susceptible.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, and the EPSS score of 0.00071 (<1 %) shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local system execution privileges; no remote code execution or elevated privileges beyond system level are needed. Attackers would need to attain local system privileges and then invoke CPM to read protected data.

Generated by OpenCVE AI on September 20, 2026 at 14:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official vendor patch or system update when released.
  • Restrict applications with system-level permissions that invoke CPM, ideally removing unnecessary system apps.
  • Configure the CPM component or surrounding services to enforce strict data access boundaries, ensuring it operates only within its intended scope.

Generated by OpenCVE AI on September 20, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Confused Deputy in CPM Enables Local Information Disclosure with System Privileges

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Potential Local Information Disclosure via Confused Deputy in CPM

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Potential Local Information Disclosure via Confused Deputy in CPM

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-15T20:32:54.008Z

Reserved: 2025-10-23T08:45:32.612Z

Link: CVE-2026-0183

cve-icon Vulnrichment

Updated: 2026-09-15T20:32:46.440Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:14.357

Modified: 2026-09-21T17:22:22.007

Link: CVE-2026-0183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')