Description
In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

In the VPU component of Android, a missing permission check can be exploited to bypass authorization controls, enabling a local user who does not require any user interaction to elevate privileges to System execution level. The vulnerability is a classic privilege‑escalation weakness, lacking proper authorization to access critical resources, and constitutes a security risk that could allow malicious apps or users to control privileged system functions.

Affected Systems

Google Android devices are affected. The the operating system; specific version details are not provided in the advisory.

Risk and Exploitability

The CVSS score of 7.8 indicates a medium-to-high severity for Local Privilege Escalation, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. This issue is not listed in the CISA KEV catalog, implying no known widespread exploitation. Attackers would need to have local access to the device and be able to run code within an unprivileged app; no user interaction is required. (This local access requirement is inferred from the lack of user interaction in the description). Once the bypass is achieved potentially leading to full device compromise.

Generated by OpenCVE AI on September 20, 2026 at 13:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Android security patch released in the September 2026 security bulletin that addresses the VPU permission check issue.
  • Use device management or app‑level restrictions to the VPU component until the patch is applied.
  • Enforce the principle of least privilege on the device by ensuring that only trusted system components receive System execution permissions.

Generated by OpenCVE AI on September 20, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Android VPU Permission Check Bypass Allows Local Privilege Escalation

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Permission Bypass in Android VPU Allows Local Privilege Escalation
Weaknesses CWE-285
CWE-732

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Permission Bypass in Android VPU Allows Local Privilege Escalation
Weaknesses CWE-285
CWE-732

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:56:32.901Z

Reserved: 2026-06-23T16:22:11.810Z

Link: CVE-2026-56982

cve-icon Vulnrichment

Updated: 2026-09-16T15:04:18.666Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:29.740

Modified: 2026-09-18T19:48:22.903

Link: CVE-2026-56982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:30:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure