Description
In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published: 2026-09-08
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

The flaw exists in several functions within DeviceAdminAdd.java, allowing a malicious application to overlay a tapjacking surface over legitimate UI elements. By presenting a hidden or deceptive interface, the attacker can trick a user into performing a tap, which grants local privilege escalation without requiring additional execution privileges. The vulnerability depends on user interaction; there is no remote code execution component.

Affected Systems

Google Android, specifically the Device Administration components used in Wear OS devices that incorporate DeviceAdminAdd.java versions preceding the latest patch release referenced in the 2026-09 security bulletin. The exact version numbers are not listed, so all affected devices before the latest update should be considered.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity vulnerability, but the EPSS score of < 1% suggests a low likelihood of exploitation at present. The absence from CISA's KEV catalog further indicates no publicly documented exploitation. Because the flaw requires user interaction and is local, the risk is moderate: an attacker with physical access to a Wear OS device can use a malicious app to exploit the overlay and gain elevated privileges. No additional execution privileges are required, and the attack cannot be launched remotely.

Generated by OpenCVE AI on September 11, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android Wear OS update that addresses the DeviceAdminAdd overlay issue.
  • If an update is not yet available, restrict or remove Device Administration permissions from applications that request overlay capabilities.
  • Disable or block overlay permissions system‑wide by adjusting developer settings or using device‑management policies to prevent new overlays from being displayed.

Generated by OpenCVE AI on September 11, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Thu, 10 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Wear OS Device Administration Overlay Privilege Escalation

Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Tapjacking in Android Device Administration
Weaknesses CWE-284

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Tapjacking in Android Device Administration
Weaknesses CWE-284

Tue, 08 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description In multiple places, there is a possible permission bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In multiple places, there is a possible permission bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:32:45.417Z

Reserved: 2026-03-02T19:11:19.580Z

Link: CVE-2026-28656

cve-icon Vulnrichment

Updated: 2026-09-10T14:27:26.237Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:56.100

Modified: 2026-09-15T14:15:03.533

Link: CVE-2026-28656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:15Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames