Description
In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

A permission bypass flaw in CPM results from a confused deputy scenario. An attacker can gain System execution privileges without user interaction, allowing local code execution at a higher privilege level. The weakness maps to the Confused Deputy vulnerability class, highlighting improper handling of authority boundaries within the component.

Affected Systems

The vulnerability affects Google Android devices that include the CPM component. Exact product and version details are not specified, but it applies to all devices running the affected CPM implementation at the time of disclosure.

Risk and Exploitability

With a CVSS score of 6.7, the flaw is considered medium severity. The EPSS score is very low (<1%) but not zero, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires only local access and does not need user interaction, making the attack surface convenient for privileged local adversaries.

Generated by OpenCVE AI on September 17, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that addresses the CPM permission bypass flaw
  • Disable or remove the CPM component if it is not required for device functionality
  • Configure device security settings to restrict CPM‑related permissions and monitor system logs for privileged access anomalies

Generated by OpenCVE AI on September 17, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Permission Bypass in CPM Leading to Local Privilege Escalation

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Permission Bypass in CPM Leading to Local Privilege Escalation

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:57.182Z

Reserved: 2026-06-23T16:10:45.837Z

Link: CVE-2026-56922

cve-icon Vulnrichment

Updated: 2026-09-15T20:58:27.183Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:27.957

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-56922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:45:17Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')