Description
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

In the MicroXR Blobstore component of Google Android XR, a missing permission check permits one installed application to read or otherwise access files belonging to another application. This flaw allows a local attacker to gain elevated privileges within the device environment, escalating from their current user context to higher privileges without the need to execute additional code. The vulnerability is categorized as a local privilege escalation, presenting a direct threat to the confidentiality and integrity of data stored by other applications.

Affected Systems

The affected product is Android XR, specifically its MicroXR Blobstore implementation. The CVE data does not list a specific version range, so any devices running Android XR with the unpatched blobstore may be impacted. No other vendors or products are currently noted as affected.

Risk and Exploitability

The CVSS score of 10.0 marks this flaw as critical, and the lack of user interaction indicates that exploitation can occur entirely from a local context. Although the EPSS score is < 1%, the absence of a CISA KEV listing suggests no confirmed exploits yet, but the condition is still severe. An attacker with local device access, which could be achieved via physical possession or by compromising an app with sufficient authority, could leverage the missing permission check to read or manipulate files of other applications, leading to potential data exfiltration or further compromise.

Generated by OpenCVE AI on September 10, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest Android XR update that includes a fixed permission check for the blobstore component.
  • Verify that MicroXR Blobstore enforces proper permissions; if remediation is not provided, configure device or app settings to restrict cross‑app file access.
  • Apply system‑level file permissions or isolated storage mechanisms to prevent unwanted file sharing between applications.
  • Stay informed about official Google security bulletins and apply them promptly.

Generated by OpenCVE AI on September 10, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android_xr:14:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 10 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android Xr
Vendors & Products Google
Google android Xr

Thu, 10 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Android XR MicroXR Blobstore Enables Local Privilege Escalation

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Local Privilege Escalation in MicroXR Blobstore
Weaknesses CWE-284

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 09 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Local Privilege Escalation in MicroXR Blobstore
Weaknesses CWE-284

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Google Android Xr
cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-09T20:37:00.386Z

Reserved: 2026-03-02T19:11:19.581Z

Link: CVE-2026-28659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:32.957

Modified: 2026-09-14T14:19:56.373

Link: CVE-2026-28659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:45:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management