Description
In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

A missing permission check in several functions of SmsController.java on Android allows a local attacker to elevate privileges without needing any additional execution rights. The flaw permits the malicious code to gain higher authority over system resources, potentially enabling control over SMS capabilities and other privileged functions. This vulnerability is classified under CWE‑269, reflecting an inadequate enforcement of authorization controls. The impact is confined to the local system, but once elevated, the attacker can execute unauthorized actions.

Affected Systems

The flaw affects Android devices running any version that includes the vulnerable SmsController implementation. The affected vendors product is Google Android, and all devices distributed by Google prior to the publication of the 2026‑09‑01 security bulletin may be impacted. Specific versions are not listed in the advisory, so any build that incorporates the referenced code is at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies this vulnerability as high severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog, indicating no currently known exploitation in the wild. The attack vector is inferred to be local: an attacker already on the device can trigger the flaw without any user interaction. The exploitation requires no additional privileges beyond what is needed to run on the device, making it straightforward for a local attacker to leverage.

Generated by OpenCVE AI on September 9, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch released in the 2026‑09‑01 bulletin.
  • Secure SMS permissions by restricting the SEND_SMS privilege to system‑level apps only, ensuring third‑party applications cannot invoke SmsController.
  • If a patch cannot be applied immediately, disable the SmsController component or remove third‑party apps that rely on SMS functionality until the fix is deployed.

Generated by OpenCVE AI on September 9, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Android SmsController privilege escalation via missing permission check

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T21:06:55.899Z

Reserved: 2026-07-02T06:06:30.647Z

Link: CVE-2026-58874

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:03.270

Modified: 2026-09-24T19:06:16.800

Link: CVE-2026-58874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T23:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management