Description
In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A flaw in Google Android allows an attacker to bypass permission checks via side‑channel information disclosure, enabling local privilege escalation without executing arbitrary code. The vulnerability stems from the improper handling of sensitive data, granting elevated access levels to the attacker. This can compromise the confidentiality, integrity, and availability of data and services on the device.

Affected Systems

This issue affects Google Android devices; specific product models and OS versions are not disclosed in the CVE data. It appears to apply broadly to devices that received the current security update documented in Google's Security Bulletin for September 1, 2026.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. The EPSS score of <1% implies a very low, but non‑zero, exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. No user interaction is required, so a local attacker could potentially exploit the side‑channel to elevate privileges. The likely attack vector is local access; this is inferred from the description that no user interaction is needed.

Generated by OpenCVE AI on September 20, 2026 at 13:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device to a version of Android that includes the security fix referenced in the Google Security Bulletin for September 1, 2026.
  • Disable or restrict any unnecessary services or applications that provide side‑channel data access through device settings or enterprise management policies.
  • Ensure the device remains locked and encrypted to reduce the window in which local privilege escalation could be attempted.

Generated by OpenCVE AI on September 20, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Android Permission Bypass via Side Channel Enables Local Privilege Escalation

Thu, 17 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Possible Permission Bypass Allowing Local Privilege Escalation via Side-Channel Information Disclosure

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Possible Permission Bypass Allowing Local Privilege Escalation via Side-Channel Information Disclosure

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:04:12.443Z

Reserved: 2026-06-23T16:05:58.746Z

Link: CVE-2026-56888

cve-icon Vulnrichment

Updated: 2026-09-15T20:29:31.794Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:24.217

Modified: 2026-09-21T17:19:16.517

Link: CVE-2026-56888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses