Impact
A flaw in Google Android allows an attacker to bypass permission checks via side‑channel information disclosure, enabling local privilege escalation without executing arbitrary code. The vulnerability stems from the improper handling of sensitive data, granting elevated access levels to the attacker. This can compromise the confidentiality, integrity, and availability of data and services on the device.
Affected Systems
This issue affects Google Android devices; specific product models and OS versions are not disclosed in the CVE data. It appears to apply broadly to devices that received the current security update documented in Google's Security Bulletin for September 1, 2026.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score of <1% implies a very low, but non‑zero, exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. No user interaction is required, so a local attacker could potentially exploit the side‑channel to elevate privileges. The likely attack vector is local access; this is inferred from the description that no user interaction is needed.
OpenCVE Enrichment