Logic Error in Call Intent Processor Allows Emergency Call Exploitation in Android
CVE-2026-28581
4MEDIUM
What is CVE-2026-28581?
A logic error in the fixInitiatingUserIfNecessary method of CallIntentProcessor.java in Android could potentially allow unauthorized users to initiate emergency calls. This vulnerability arises from a flaw in the code that fails to properly verify execution privileges, leaving room for exploitation without requiring user interaction.
Affected Version(s)
Android 16-qpr2
Android 16
Android 15