Local Escalation of Privilege in Android Auto Product by Google
CVE-2026-28641

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-28641?

A permission bypass vulnerability exists in the ApplicationActionButtonsPreferenceController.java of Android Auto. This issue stems from a logic error in the code, which may allow an attacker to escalate privileges locally without needing additional execution privileges or user interaction. Addressing this issue is critical to maintaining the security and integrity of the affected environment.

Affected Version(s)

Android 16-qpr2

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.