Description
In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The flaw lies in the onAttach method of BiometricsSettingsBase.java, where a confused‑deputy error enables an attacker to bypass authentication checks and gain elevated privileges locally. No additional execution rights or user interaction are required, so any local process with code execution can exploit it, allowing the attacker to perform actions normally restricted to higher‑privileged users.

Affected Systems

Affected systems are all Google Android devices that include the susceptible version of BiometricsSettingsBase. The CVE does not specify a particular Android release, so any device bearing the vulnerable implementation may be impacted; users should look for the September 2026 security patch in the Android firmware.

Risk and Exploitability

The vulnerability is a local privilege escalation with a CVSS score of 7.8, indicating moderate‑to‑high severity. The EPSS score of less than 1% suggests a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Because the flaw is a confused‑deputy weakness, an attacker can trigger it by simply attaching to BiometricsSettingsBase from a local process, bypassing expected authentication controls and elevating privileges on the device.

Generated by OpenCVE AI on September 11, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update your device to the latest Android firmware that includes the September 2026 security patch for BiometricsSettingsBase.
  • Restrict app permissions that allow processes to bind to BiometricsSettingsBase using system controls or enterprise MDM policies, limiting attachment to trusted components.
  • Monitor device logs for unexpected binding attempts to BiometricsSettingsBase and enforce least‑privilege boundaries on system services.

Generated by OpenCVE AI on September 11, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authentication Bypass in Android BiometricsSettingsBase
Weaknesses CWE-287
CWE-360

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Authentication Bypass in Android BiometricsSettingsBase
Weaknesses CWE-287
CWE-360

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:10:12.854Z

Reserved: 2026-05-12T17:34:26.824Z

Link: CVE-2026-45520

cve-icon Vulnrichment

Updated: 2026-09-10T14:10:08.355Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:57.630

Modified: 2026-09-24T15:25:44.783

Link: CVE-2026-45520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:15Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')