Description
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The flaw exists in the platform_msg_handler_init function of default_msg_handlers.c, where a confused deputy bug (CWE‑441) allows a component running with lower privileges to act as if it had elevated System execution rights; this can be exploited locally without any user interaction.

Affected Systems

All Android devices that run the default_msg_handlers implementation and have not applied the September 2026 security update referenced in the Android security bulletin; the vendor is Google and the product is the Android operating system.

Risk and Exploitability

The CVSS score of 6.7 indicates medium severity and the EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because it can be triggered locally without user interaction, the risk remains significant for any device that may execute untrusted code. The likely attack vector is a local compromise scenario where a malicious process crafts messages that are processed by the default message handlers, escalating its privileges to System level.

Generated by OpenCVE AI on September 20, 2026 at 14:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Android 2026‑09 security patch that corrects the platform_msg_handler_init flaw.
  • Restrict the ability of untrusted applications to interact with the message handler by tightening permission checks or adding sandboxing so that only trusted processes with appropriate privileges can send messages.
  • As a temporary measure, disable or reconfigure services that load the default message handlers until the corrected firmware is installed, reducing the potential surface for confused‑deputy exploitation.

Generated by OpenCVE AI on September 20, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in Android Message Handler

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Confused Deputy in Android Message Handler

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:17.082Z

Reserved: 2026-07-02T05:42:12.104Z

Link: CVE-2026-58739

cve-icon Vulnrichment

Updated: 2026-09-15T19:47:12.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:33.343

Modified: 2026-09-18T12:59:35.917

Link: CVE-2026-58739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')