Permission Bypass Vulnerability in Android System
CVE-2026-28625

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-28625?

A vulnerability exists within the Android System that allows for a potential permission bypass due to a logic error in the codebase. This flaw can enable local escalation of privileges without requiring any additional execution privileges. Notably, the exploitation of this vulnerability does not necessitate user interaction, potentially putting systems at risk.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.