Impact
A missing permission check in the isSystem method of WifiPermissionsUtil.java allows a locally running application to elevate its privileges without requiring any user interaction. The flaw effectively lets the app gain system level access on the Android device, potentially allowing it to read or modify any data, control device settings, or execute arbitrary code under the device’s system context. This issue is best described by the CWE classifications of Improper Access Control and Execution with Privileges Higher Than Required.
Affected Systems
The vulnerability affects devices running Google Android where the compromised WifiPermissionsUtil code is present. No specific version numbers are mentioned in the advisory, so any Android OS release that includes the affected implementation is at risk. Users should consider that the issue is addressed in the Android 2026‑10‑01 security bulletin, but all devices shipped before that patch are potentially vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Without a published CVSS score we cannot quantify the severity, but because the flaw is local and requires no additional execution or user interaction, an attacker with access to the device can immediately elevate privileges. The lack of a publicly disclosed exploit or exploit probability makes the likelihood of attack uncertain, yet the potential impact remains high should an attacker gain a foothold. The official solution involves installing the Android 2026‑10‑01 patch from Google's security bulletin.
OpenCVE Enrichment