Description
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Update Device
AI Analysis

Impact

Android contains a logic error that allows a permission‑bypass in multiple code paths. The flaw can be triggered by local users with normal execution rights, enabling them to modify system files or execute code that requires higher privileges. The impact is a classic local privilege escalation that affects confidentiality, integrity, and availability of the device.

Affected Systems

The vulnerability applies to Android devices sold by Google, including Pixel phones. The exact Android release versions are not specified in the advisory, but the issue is mentioned in the 2026‑09‑01 security bulletin.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score of less than 1% shows that exploitation is unlikely but possible. The flaw does not need user interaction; an attacker who gains local execution can elevate privileges automatically. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 20, 2026 at 14:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security update that fixes the permission‑bypass flaw.
  • If a patch is not yet available, restrict the relevant application's permissions or disable the vulnerable functionality.
  • Continuously monitor Google’s Android security bulletins and apply any new patch as soon as it is released.

Generated by OpenCVE AI on September 20, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Permission Bypass Leading to Local Privilege Escalation in Android

Thu, 17 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Android Permission Bypass Allowing Local Privilege Escalation
Weaknesses CWE-269
CWE-287

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Android Permission Bypass Allowing Local Privilege Escalation
Weaknesses CWE-269
CWE-287

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:49.266Z

Reserved: 2026-06-16T17:55:41.478Z

Link: CVE-2026-55359

cve-icon Vulnrichment

Updated: 2026-09-16T15:45:09.962Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:21.833

Modified: 2026-09-21T17:19:47.730

Link: CVE-2026-55359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure