Description
In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An integer overflow in the Android permission handling subsystem allows a permissive bypass, enabling a process running with normal user privileges to elevate itself to System execution privileges. The flaw arises when arithmetic operations fail, resulting in an incorrect authorization decision that grants undue access. This bypass can be leveraged to install or run privileged code on the device without needing any user interaction, potentially compromising device integrity and confidentiality.

Affected Systems

The vulnerability applies to Google Android devices; no specific version was listed in the advisory. All builds affected by the identified integer overflow are potentially impacted, regardless of release channel or device model.

Risk and Exploitability

The exploit requires local code execution on an unpatched Android device. Because user interaction is not needed, any local process or user can trigger the integer overflow. The flaw has a CVSS score of 6.7, indicating medium severity, and its EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, since local privilege escalation can undermine device integrity and confidentiality, the risk to affected devices remains significant.

Generated by OpenCVE AI on September 20, 2026 at 13:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the September 2026 security patch for Android as described in the official security bulletin
  • Upgrade the device to the latest available Android firmware that includes the fix
  • Restrict installation of apps from unknown or unverified sources to prevent exploitation of local software vulnerabilities

Generated by OpenCVE AI on September 20, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow Permission Bypass Allowing Local Privilege Escalation on Android

Thu, 17 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Android Permission Handling Allows Local Privilege Escalation

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Android Permission Handling Allows Local Privilege Escalation
Weaknesses CWE-190

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:45.996Z

Reserved: 2026-06-23T16:05:58.746Z

Link: CVE-2026-56889

cve-icon Vulnrichment

Updated: 2026-09-16T15:31:34.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:24.353

Modified: 2026-09-21T17:19:11.970

Link: CVE-2026-56889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:00:26Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound