Permission Bypass Vulnerability in Bootloader by Android Inc.
CVE-2026-58678

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-58678?

A vulnerability exists in the Bootloader due to a logic error in the code, potentially allowing attackers to bypass permission settings. This flaw can facilitate a local escalation of privileges, enabling unauthorized access with elevated system execution privileges. Notably, exploitation of this vulnerability does not require user interaction, posing a significant risk to affected devices. Organizations should remain vigilant and implement necessary mitigation measures to safeguard their systems.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.