Impact
A missing permission check in several functions of SmsController.java on Android allows a local attacker to elevate privileges without needing any additional execution rights. The flaw permits the malicious code to gain higher authority over system resources, potentially enabling control over SMS capabilities and other privileged functions. This vulnerability is classified under CWE‑269, reflecting an inadequate enforcement of authorization controls. The impact is confined to the local system, but once elevated, the attacker can execute unauthorized actions.
Affected Systems
The flaw affects Android devices running any version that includes the vulnerable SmsController implementation. The affected vendors product is Google Android, and all devices distributed by Google prior to the publication of the 2026‑09‑01 security bulletin may be impacted. Specific versions are not listed in the advisory, so any build that incorporates the referenced code is at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog, indicating no currently known exploitation in the wild. The attack vector is inferred to be local: an attacker already on the device can trigger the flaw without any user interaction. The exploitation requires no additional privileges beyond what is needed to run on the device, making it straightforward for a local attacker to leverage.
OpenCVE Enrichment