Improper Input Validation in Android Credential Storage Activity
CVE-2026-28640

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-28640?

A vulnerability in the checkCallerIsCertInstallerOrSelfInProfile method of CredentialStorageActivity.java can allow a potential permission bypass due to improper input validation. This flaw could enable local escalation of privilege without the requirement of additional execution privileges or user interaction for successful exploitation.

Affected Version(s)

Android 16

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.