Description
In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

In some versions of the Android bootloader a permission check is omitted, allowing an attacker to gain System execution privileges without any user interaction. This missing check is a form of Broken Access Control (CWE-862).

Affected Systems

The flaw exists in Google Android devices; all Android bootloaders that contain the missing permission check are affected. Specific affected versions are not listed, so any Android device running a bootloader containing this check could be vulnerable.

Risk and Exploitability

The exploit requires local access to the device and occurs during the boot process, so no user interaction is needed. The EPSS score of < 1 % indicates a very low probability of widespread exploitation, but the CVSS score of 6.7 reflects moderate severity. The vulnerability is not listed in CISA KEV, and a successful attack would grant system execution privileges, effectively compromising the device.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Android security update from Google as soon as it is released.
  • If a patch is not yet available, restrict physical access to the device and disable any bootloader customization or recovery setups that are not signed by Google.
  • Enable secure boot and full disk encryption to reduce the risk of bootloader tampering and protect data if the device is compromised.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Bootloader Missing Permission Check Enables Local Privilege Escalation

Sun, 20 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Android Bootloader Allows Local Privilege Escalation
Weaknesses CWE-272

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Android Bootloader Allows Local Privilege Escalation
Weaknesses CWE-272

Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:56:04.478Z

Reserved: 2025-10-23T08:45:44.678Z

Link: CVE-2026-0192

cve-icon Vulnrichment

Updated: 2026-09-16T16:55:59.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:14.757

Modified: 2026-09-21T17:21:52.440

Link: CVE-2026-0192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses