Description
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Apply Update
AI Analysis

Impact

Android has a logic error that allows a permission bypass in multiple code paths. An attacker with user‑level execution privileges can use this flaw to gain higher privileges on the device, potentially enabling the modification of system files or execution of privileged code. This type of vulnerability enables an attacker to compromise confidentiality, integrity, and availability of the affected device without relying on third‑party input or malicious user interaction.

Affected Systems

The vulnerability applies to Android devices sold by Google, including Pixel phones. The specific affected Android releases are not listed, but the issue exists in the current Android code base as of the latest security bulletin.

Risk and Exploitability

The CVE is not listed in the CISA KEV catalog and no EPSS score is available, so the exploitation probability is currently unknown. Exploitation requires local device access and user execution privileges but does not need user interaction, meaning an attacker could potentially elevate privileges automatically after gaining a foothold. The severity of this local privilege escalation warrants timely remediation.

Generated by OpenCVE AI on September 15, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest Android security release that includes the permission‑bypass fix.
  • If a recent update is not yet available, restrict the affected application’s permissions or disable the vulnerable features if possible.
  • Monitor Google’s Android security bulletins for the release of a patch and apply it as soon as it becomes available.

Generated by OpenCVE AI on September 15, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Android Permission Bypass Allowing Local Privilege Escalation
Weaknesses CWE-269
CWE-287

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:49.266Z

Reserved: 2026-06-16T17:55:41.478Z

Link: CVE-2026-55359

cve-icon Vulnrichment

Updated: 2026-09-16T15:45:09.962Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:21.833

Modified: 2026-09-17T04:17:47.543

Link: CVE-2026-55359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-693

    Protection Mechanism Failure