Junglewise Threat Intelligence

CVE-2025-26418: Google Android privilege escalation in CarDevicePolicyService

CVE-2025-26418 · Severity: info · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android CarDevicePolicyService allows for the bypass of user confirmation dialogs when adding accounts to a managed device. This could allow a local attacker or malicious application to gain elevated privileges on the system without the user's knowledge or consent. This issue primarily affects managed Android devices, such as those used in corporate or automotive environments.

Technical details

A privilege escalation vulnerability exists in the 'setUserDisclaimerAcknowledged' method within 'CarDevicePolicyService.java' due to a missing permission check. A local attacker can exploit this flaw to bypass the mandatory user disclaimer dialog when adding a new account to a managed device. This bypass facilitates local escalation of privilege (EoP) without requiring any special execution privileges or user interaction. The vulnerability is addressed in the June 2026 Android Security Bulletin for Android versions 14 and 15.

Affected products

  • Google Android 14, 15

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: disclosed

References

Related threats