Permission Bypass Vulnerability in Android Device Admin Apps by Google
CVE-2026-28647

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-28647?

A logic error in the updateState method of DeviceAdminAppsPreferenceController.java in Android may allow for a local escalation of privilege. Exploitation of this vulnerability does not require any additional execution privileges or user interaction, thereby potentially compromising the security of the affected device.

Affected Version(s)

Android 16-qpr2

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.