Description
In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability lies in a logic error within the GPU component of the Android operating system. It permits a local attacker to bypass permission checks, which can lead to the execution of code with system privileges. This flaw is classified as CWE-693 and does not require remote interaction or user involvement, so any user with access to the device may exploit it.

Affected Systems

The flaw affects Google Android devices. Specific affected OS versions are not listed in the advisory; however, the security bulletin linked provides details for the latest patch cycle available at the time. Users should check the release notes for their device model to confirm whether the GPU code in their Android version incorporates the fix.

Risk and Exploitability

The CVSS score is 6.7, indicating a moderate risk. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation is local only, requiring the attacker to have physical or local access to the device, and does not need user interaction. As a result, the risk is significant for users who have screen access to the device or who leave it unlocked, but is less relevant for remote or unattended scenarios.

Generated by OpenCVE AI on September 17, 2026 at 08:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch released in the September 2026 bulletin, which addresses the GPU permission bypass.
  • After applying the patch, reboot the device to ensure the updated libraries are loaded into memory.
  • If patching is delayed, consider disabling GPU acceleration for applications that do not require high‑performance graphics or running in a least‑privilege sandbox to limit potential escalation paths.

Generated by OpenCVE AI on September 17, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title GPU Permission Bypass Enabling Local Privilege Escalation on Android

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title GPU Permission Bypass Enabling Local Privilege Escalation on Android

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:11.268Z

Reserved: 2026-07-02T05:46:59.932Z

Link: CVE-2026-58765

cve-icon Vulnrichment

Updated: 2026-09-15T19:30:57.563Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:33.827

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-58765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure