Description
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: n/a
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Apply Updates
AI Analysis

Impact

In the FsmReleaseKey function within fsm.c, a flaw allows an application to bypass permission checks because input is not properly validated. As a result, an attacker can gain higher privileges on the device with the user. The weakness can be classified as an improper input validation vulnerability that permits a permission bypass, potentially exposing the system to unauthorized actions.

Affected Systems

This vulnerability affects Google's Android operating system. Specific affected Android versions are not disclosed in the CVE data, so any installation of Android that includes the FsmReleaseKey implementation could be vulnerable. The weakness lies in the system-level handling of this function rather than in a particular application.

Risk and Exploitability

The vulnerability is local and requires no special user interaction; an attacker with access to the device can exploit it. The exploit does not rely on remote code execution but exploits local privilege escalation. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, however the severity of the impact suggests a high-level risk if present. The likely attack vector is a local attacker or malware on the device that can call the vulnerable function.

Generated by OpenCVE AI on September 16, 2026 at 00:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Android where the permission validation in FsmReleaseKey has been corrected.
  • Add explicit validation checks for all inputs to FsmReleaseKey to ensure only authorized requests are processed.
  • Enforce strict access controls using SELinux or similar mechanisms so that only trusted system components can invoke Fsmous calls to FsmReleaseKey and audit permission usage to detect potential exploitation.

Generated by OpenCVE AI on September 16, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-15T18:34:33.044Z

Reserved: 2026-07-02T05:35:39.177Z

Link: CVE-2026-58691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T19:17:31.800

Modified: 2026-09-15T19:17:31.800

Link: CVE-2026-58691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses

No weakness.