Impact
Android contains a logic error that allows a permission‑bypass in multiple code paths. The flaw can be triggered by local users with normal execution rights, enabling them to modify system files or execute code that requires higher privileges. The impact is a classic local privilege escalation that affects confidentiality, integrity, and availability of the device.
Affected Systems
The vulnerability applies to Android devices sold by Google, including Pixel phones. The exact Android release versions are not specified in the advisory, but the issue is mentioned in the 2026‑09‑01 security bulletin.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score of less than 1% shows that exploitation is unlikely but possible. The flaw does not need user interaction; an attacker who gains local execution can elevate privileges automatically. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment