Description
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The flaw is an improper input validation that allows an attacker to supply specially crafted data to the Android kernel or framework. This bypasses standard checks and permits local privilege escalation, enabling an attacker to gain higher privileges without additional execution rights. The core weakness is identified as CWE-20, which pertains to boundary checks or validation failures, and can undermine the confidentiality, integrity, and availability of the device.

Affected Systems

Android devices running Android versions that have not received the September 2026 security update are affected. The vulnerability spans multiple kernel and framework components noted in the Android security bulletin; no precise build numbers are provided, so any device prior to the latest patch may be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity, while the EPSS score of 0.00068 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local, with no requirement for user interaction; a malicious application or a compromised component could deliver the crafted data leading to exploitation on the device.

Generated by OpenCVE AI on September 20, 2026 at 13:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that contains the input validation fix
  • Restrict installations to verified, signed applications and disable installation from unknown sources
  • Implement mobile device management to enforce least‑privilege policies and monitor privileged application behavior

Generated by OpenCVE AI on September 20, 2026 at 13:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Improper Input Validation in Android

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in Android

Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper Input Validation in Android

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:15.695Z

Reserved: 2026-07-02T05:43:30.493Z

Link: CVE-2026-58744

cve-icon Vulnrichment

Updated: 2026-09-15T19:46:04.565Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:33.440

Modified: 2026-09-18T12:59:42.120

Link: CVE-2026-58744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:15:14Z

Weaknesses
  • CWE-20

    Improper Input Validation