Executive brief
A security vulnerability exists in the SettingsLib component of Android 17. This flaw allows a local application to gain higher system privileges than it should normally have without any user interaction. This could potentially allow a malicious app to bypass security restrictions and access sensitive system functions or data.
Technical details
A logic error in the SettingsLib component of Android 17 results in a missing permission check (CWE-862). This vulnerability allows a local attacker to achieve escalation of privilege (EoP) without requiring additional execution privileges or user interaction. While the CNA-provided CVSS 4.0 vector suggests a network attack vector (AV:N), the vulnerability description and Android security bulletin categorize this as a local escalation of privilege. The issue is addressed in the Android 17 security patch level 2026-07-01.
Affected products
- Google Android 17
Timeline
- 2026-06-16: disclosed: Initial bulletin publication date
- 2026-06-17: advisory: NVD publication date
- 2026-07-01: patched: Security patch level date for Android 17