Permission Bypass Vulnerability in Android Communication System by Google
CVE-2026-58698

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-58698?

A vulnerability exists within the ap_pmic_poll_msg_handler function in ap_pmic_ipc.c, where a confused deputy pattern allows for a possible permission bypass. This flaw could enable local users to escalate their privileges to System execution level without requiring any user interaction. Security patches and mitigations are critical for protecting affected Android devices from potential exploitation.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.