Impact
A permission bypass exists in Android’s SlicePermissionActivity during its onCreate method due to a confused deputy flaw (CWE-441), allowing a local attacker to gain higher privileges without needing additional execution rights or user interaction. The attacker can elevate its own privileges, potentially accessing restricted resources, modifying system settings, or installing malicious applications.
Affected Systems
The vulnerability affects Google’s Android operating system. The public advisory references the Android Security Bulletin for September 2026, indicating that affected Android versions are listed in that bulletin, though specific release ranges are not detailed in the data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, while the EPSS score is less than exploitation currently. The vulnerability is not listed in CISA’s KEV catalog, implying no known exploitation in the wild as of its reporting. Nonetheless, because no user interaction is required and any local attacker or malicious app on the device can trigger the flaw, it presents a significant potential impact. The flaw’s core weakness is a permission bypass arising access control flaw.
OpenCVE Enrichment