Impact
The flaw exists in several functions within DeviceAdminAdd.java, allowing a malicious application to overlay a tapjacking surface over legitimate UI elements. By presenting a hidden or deceptive interface, the attacker can trick a user into performing a tap, which grants local privilege escalation without requiring additional execution privileges. The vulnerability depends on user interaction; there is no remote code execution component.
Affected Systems
Google Android, specifically the Device Administration components used in Wear OS devices that incorporate DeviceAdminAdd.java versions preceding the latest patch release referenced in the 2026-09 security bulletin. The exact version numbers are not listed, so all affected devices before the latest update should be considered.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability, but the EPSS score of < 1% suggests a low likelihood of exploitation at present. The absence from CISA's KEV catalog further indicates no publicly documented exploitation. Because the flaw requires user interaction and is local, the risk is moderate: an attacker with physical access to a Wear OS device can use a malicious app to exploit the overlay and gain elevated privileges. No additional execution privileges are required, and the attack cannot be launched remotely.
OpenCVE Enrichment