Description
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The flaw is an improper input validation that allows an attacker to supply specially crafted data to the Android kernel or framework. This bypasses standard checks and permits local privilege escalation, enabling an attacker to gain higher privileges without additional execution rights. The core weakness is identified as CWE-20, which pertains to boundary checks or validation failures, and can undermine the confidentiality, integrity, and availability of the device.

Affected Systems

Android devices running Android versions that have not received the September 2026 security update are affected. The vulnerability spans multiple kernel and framework components noted in the Android security bulletin; no precise build numbers are provided, so any device prior to the latest patch may be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity, while the EPSS score of 0.00068 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local, with no requirement for user interaction; a malicious application or a compromised component could deliver the crafted data leading to exploitation on the device.

Generated by OpenCVE AI on September 17, 2026 at 08:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that contains the input validation fix
  • Restrict installations to verified, signed applications and disable installation from unknown sources
  • Implement mobile device management to enforce least-privilege policies and monitor privileged application behavior

Generated by OpenCVE AI on September 17, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in Android

Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in Android

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:15.695Z

Reserved: 2026-07-02T05:43:30.493Z

Link: CVE-2026-58744

cve-icon Vulnrichment

Updated: 2026-09-15T19:46:04.565Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:33.440

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-58744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses
  • CWE-20

    Improper Input Validation