Permission Bypass Vulnerability in Android AppOpsService by Google
CVE-2026-28586

3.3LOW

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-28586?

A vulnerability exists in multiple functions of AppOpsService.java in Google's Android platform due to missing permission checks. This flaw allows for potential local information disclosure without the need for additional execution privileges, and crucially, no user interaction is required for exploitation. This creates risks for sensitive data exposure, emphasizing the importance of prompt remediation and security best practices within affected Android versions.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.