Local Escalation of Privilege in Android Auto Product by Google
CVE-2026-28641
Currently unrated
What is CVE-2026-28641?
A permission bypass vulnerability exists in the ApplicationActionButtonsPreferenceController.java of Android Auto. This issue stems from a logic error in the code, which may allow an attacker to escalate privileges locally without needing additional execution privileges or user interaction. Addressing this issue is critical to maintaining the security and integrity of the affected environment.
Affected Version(s)
Android 16-qpr2
Android 15
Android 14