Description
In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in AndroidManifest.xml is a missing permission check that enables an attacker to provoke a persistent denial of service. The flaw is classified as CWE‑862: Missing Permission. Without any additional privileges, a local adversary can trigger a crash or halt of the targeted component or service. The impact is confined to the affected app or service rather than the entire OS; based on the description, it is inferred that the denial requires local access to the vulnerable component.

Affected Systems

The flaw targets Google Android, including Wear OS, as referenced by the 2026/06/01 security bulletin. The CPE list indicates versions 14.0 and 16.0 of Google Android, as well as any Wear OS device. Specific version patches are not disclosed, so any device running the vulnerable software is potentially affected.

Risk and Exploitability

The CVSS base score of 10.0 marks the flaw as critical. The EPSS score of less than 1% indicates a low exploitable probability at present. The vulnerability is locally exploitable without privilege escalation or user interaction, so any device with the affected component is at risk. It is not yet listed in CISA KEV, so no known exploitation is documented, but the severity and local nature warrant prompt remediation.

Generated by OpenCVE AI on August 12, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android OS update that incorporates the permission check fix
  • If an update is not available, restrict or uninstall the vulnerable application
  • Android app developers must add explicit permission checks in the AndroidManifest and enforce them in code before starting services

Generated by OpenCVE AI on August 12, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service from Missing Permission Check in AndroidManifest

Mon, 22 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service from Missing Permission Check in AndroidManifest

Mon, 22 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service via Missing Permission Check in AndroidManifest.xml
Weaknesses CWE-284

Mon, 22 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Thu, 18 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service via Missing Permission Check in AndroidManifest.xml
Weaknesses CWE-284

Thu, 18 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-22T16:37:29.664Z

Reserved: 2026-03-02T19:10:53.531Z

Link: CVE-2026-28573

cve-icon Vulnrichment

Updated: 2026-06-18T13:00:27.906Z

cve-icon NVD

Status : Modified

Published: 2026-06-18T08:16:33.853

Modified: 2026-06-22T18:16:35.153

Link: CVE-2026-28573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T02:30:04Z

Weaknesses