Impact
In multiple functions of the Android NfcService, a missing permission check could enable a silent payment session hijack. An attacker with local access could hijack a payment session without obtaining any additional execution privileges or needing user interaction. This flaw represents an internal escalation of privilege and can lead to unauthorized manipulation of payment transactions.
Affected Systems
The affected Google Android releases include all versions that contain the vulnerable NfcService code until the patch is applied, as the specific version information is not disclosed in the CVE data.
Risk and Exploitability
Because the exploit requires local access and no user interaction, the attack vector is local. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low likelihood of exploitation in the near term. This flaw also maps to CWE‑862, highlighting a missing authorization check in addition to the missing permission. With a CVSS score of 7.8 the vulnerability is considered substantial2026‑09‑01 security bulletin; installing the patch removes the missing permission check and mitigates the risk.
OpenCVE Enrichment