Executive brief
Android's face enrollment functionality contains a privilege escalation vulnerability in the FaceEnroll.kt component. An attacker with local access to a device can exploit this confused deputy flaw to gain elevated privileges without requiring additional permissions or user interaction, potentially compromising the security of the entire device.
Technical details
The vulnerability is a confused deputy attack in multiple functions of FaceEnroll.kt that enables local privilege escalation on Android. The root cause involves improper permission delegation or validation in the face enrollment subsystem, allowing an attacker to bypass privilege checks. No additional execution privileges are required for exploitation, and user interaction is not needed. The vulnerability allows an attacker to escalate from a lower privilege context to a higher one, potentially gaining system-level access. Patches are available in Android 14 and later versions through the Android security patch level 2026-09-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2, 17
Timeline
- 2026-03-02: disclosed
- 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue