Executive brief
A security flaw in Android 17 could allow an unauthorized person physically near a device to bypass security checks during the passkey pairing process. This could allow an attacker to link a third-party device or credential to a user's account without their permission or interaction. If exploited, this could lead to unauthorized access to sensitive personal data or account takeover.
Technical details
A vulnerability in the System component of Android 17 arises from a missing permission check in multiple locations related to 3rd party passkey entry pairing. An attacker in proximal or adjacent range can exploit this flaw to achieve elevation of privilege without requiring any additional execution privileges or user interaction. The vulnerability is classified as CWE-862 (Missing Authorization). Google has addressed this in the Android 17 security release with a default security patch level of 2026-07-01.
Affected products
- Google Android 17
Timeline
- 2026-06-16: advisory: Initial Android 17 Security Release Notes published
- 2026-06-17: disclosed: CVE-2025-48640 published to NVD