Description
In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Assess
AI Analysis

Impact

The vulnerability arises from a missing permission check in the openFile routine of AppFuseBridge.java, an integral part of the Android framework. The omission allows any local app or process to read protected files through the exposed file opening interface, resulting in information disclosure. This weakness is classified as CWE-693 (Improper Check of Security‑relevant Information). Because no elevated privileges are required, a local attacker can extract data that would otherwise be protected by the platform’s permission model.

Affected Systems

Google Android builds that include the AppFuseBridge component are affected. The advisory does not specify particular hardware or OS versions, implying that all Android releases incorporating this component without the patch may be vulnerable. The flaw resides in the core framework rather than a third‑party app.

Risk and Exploitability

The calculated CVSS score is 3.3, indicating low severity. EPSS is below 1%, showing a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits are documented. The attack vector is purely local; an adversary already on the device could invoke the openFile function from a malicious or compromised app without user interaction. Because missing authorization (CWE-693) leads to insecure data exposure, the risk to individual devices is low but confined to local contexts.

Generated by OpenCVE AI on September 10, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update that includes the AppFuseBridge fix
  • Enforce proper permission checks (CWE-693) in any application before invoking AppFuseBridge to ensure only authorized calls are allowed
  • Restrict file access through SELinux policies or adjust file permissions to limit exposure of sensitive content
  • Monitor file‑open events with logging and anomaly detection to detect unauthorized access attempts

Generated by OpenCVE AI on September 10, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Android AppFuseBridge Information Disclosure via Missing Permission Check
Weaknesses CWE-200
CWE-284

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Android AppFuseBridge Information Disclosure via Missing Permission Check
Weaknesses CWE-200
CWE-284

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:43:08.543Z

Reserved: 2026-05-12T17:34:26.824Z

Link: CVE-2026-45521

cve-icon Vulnrichment

Updated: 2026-09-10T15:43:01.252Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:57.723

Modified: 2026-09-24T15:25:11.827

Link: CVE-2026-45521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure