Description
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

In SettingsFragment, the getItemList method can be exploited by a local attacker through a misleading or insufficient UI that bypasses user interaction. The flaw permits an attacker to elevate privileges without additional execution rights, allowing local privilege escalation. The vulnerability is triggered without user involvement, meaning the attacker can execute it automatically once the device is compromised.

Affected Systems

Google Android is flaw located in the SettingsFragment component of the Android framework. No specific affected versions are listed, so the issue applies to any Android build that contains the vulnerable getItemList method.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not in the CISA KEV catalog, suggesting it may not be actively exploited; however, as the attack vector is a local exploit that can run without additional execution privileges, operators should regard this as a high‑risk local privilege escalation. The likely attack path is inferred to be a local privilege escalation via UI bypass.

Generated by OpenCVE AI on September 11, 2026 at 05:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade your device to the latest Android firmware that includes the fix for the SettingsFragment getItemList UI bypass in the 2026‑09‑01 Security Bulletin.
  • If an update is not available, reduce exposure by disabling or restricting the affected settings entry through device‑management or custom configuration, thereby preventing the UI from being privilege escalation attempts and audit applications that can invoke Settings to detect any unauthorized activity.
  • Configure device management policies to lock the affected settings and prevent unauthorized changes to critical configuration areas.

Generated by OpenCVE AI on September 11, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title UI Bypass Leading to Local Privilege Escalation in Android SettingsFragment

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title User Interaction Bypass in SettingsFragment Causing Local Privilege Escalation
Weaknesses CWE-640

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-356
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title User Interaction Bypass in SettingsFragment Causing Local Privilege Escalation
Weaknesses CWE-640

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:10:28.698Z

Reserved: 2026-03-02T19:11:02.945Z

Link: CVE-2026-28593

cve-icon Vulnrichment

Updated: 2026-09-10T15:10:25.882Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:52.043

Modified: 2026-09-15T14:25:06.937

Link: CVE-2026-28593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:15:17Z

Weaknesses
  • CWE-356

    Product UI does not Warn User of Unsafe Actions