Impact
The flaw lies in the onAttach method of BiometricsSettingsBase.java, where a confused‑deputy error enables an attacker to bypass authentication checks and gain elevated privileges locally. No additional execution rights or user interaction are required, so any local process with code execution can exploit it, allowing the attacker to perform actions normally restricted to higher‑privileged users.
Affected Systems
Affected systems are all Google Android devices that include the susceptible version of BiometricsSettingsBase. The CVE does not specify a particular Android release, so any device bearing the vulnerable implementation may be impacted; users should look for the September 2026 security patch in the Android firmware.
Risk and Exploitability
The vulnerability is a local privilege escalation with a CVSS score of 7.8, indicating moderate‑to‑high severity. The EPSS score of less than 1% suggests a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. Because the flaw is a confused‑deputy weakness, an attacker can trigger it by simply attaching to BiometricsSettingsBase from a local process, bypassing expected authentication controls and elevating privileges on the device.
OpenCVE Enrichment