Description
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction is needed for exploitation.
Published: 2026-06-01
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Emergency Call
Action: Patch When Available
AI Analysis

Impact

A logic error in Android’s CallIntentProcessor allows a local user to trigger an emergency call without performing the expected permission checks. The flaw resides in the fixInitiatingUserIfNecessary method and requires the attacker to have normal user execution privileges and user interaction to activate a call intent. While the vulnerability does not provide remote code execution or data exfiltration, it enables a legitimate emergency number such as 911 to be dialed automatically from a user‑level application, potentially leading to false emergency responses and unnecessary police or ambulance dispatches. The CVSS score of 4.0, which is categorized as medium severity, reflects the potential impact of this local escalation.

Affected Systems

The vulnerability affects all Android releases that include the CallIntentProcessor module, namely Android 14.0 and 15.0 as well as Android 16.0 and its qpr2 beta builds (qpr2_beta_1, qpr2_beta_2, qpr2_beta_3). Every device running any of these releases and not yet patched by the vendor’s security bulletin is potentially exploitable.

Risk and Exploitability

The CVSS score is 4.0, indicating medium severity, and the EPSS score is below 1%, showing a very low probability of exploitation. The flaw is local and requires a user to initiate the call intent, therefore casual or automated attacks are unlikely. An attacker with physical or logical access can exploit the vulnerability by launching an application that requests an emergency call, but no remote attack vector is apparent. The vulnerability is not listed in CISA’s KEV catalog, which suggests no known active exploitation at present.

Generated by OpenCVE AI on September 10, 2026 at 06:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Android update that contains the vendor‑supplied fix for the CallIntentProcessor logic error, as documented in the latest security bulletin.
  • Ensure devices run the most recent Android release or apply any available patch promptly, especially for Android 14, 15 and 16 series, to close the flaw.
  • Maintain application permission hygiene by vetting third‑party apps that request emergency call capabilities and block installation of untrusted applications that unexpectedly request such permissions.

Generated by OpenCVE AI on September 10, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Emergency Call via Logic Error in Android Call Intent Processor

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation. In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction is needed for exploitation.
References

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*

Wed, 03 Jun 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Emergency Call via Logic Error in Android Call Intent Processor

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Emergency Call Bypass Without User Interaction
Weaknesses CWE-269
CWE-284

Tue, 02 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Tue, 02 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Emergency Call Bypass Without User Interaction
Weaknesses CWE-269
CWE-284

Tue, 02 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Android Logic Error Enabling Unauthenticated Emergency Calls
Weaknesses CWE-269
CWE-284

Tue, 02 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Mon, 01 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Android Logic Error Enabling Unauthenticated Emergency Calls
Weaknesses CWE-269
CWE-284

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T18:04:38.030Z

Reserved: 2026-03-02T19:10:53.531Z

Link: CVE-2026-28581

cve-icon Vulnrichment

Updated: 2026-06-01T22:39:03.906Z

cve-icon NVD

Status : Modified

Published: 2026-06-01T22:16:25.110

Modified: 2026-09-08T19:17:51.403

Link: CVE-2026-28581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:45:12Z

Weaknesses