Executive brief
A security flaw in the Near Field Communication (NFC) component of Android 17 allows for the spoofing of NFC events. This could allow a malicious application or actor to gain elevated system privileges without any user interaction. Such an exploit could lead to unauthorized access to sensitive data or control over device functions typically restricted to the operating system.
Technical details
A vulnerability in the Android NFC component arises from a missing permission check during the handling of NFC events. An attacker can exploit this to spoof NFC signals, leading to local escalation of privilege (EoP) without requiring additional execution privileges or user interaction. While the NVD description categorizes this as local escalation, the provided CVSS 4.0 vector from the CNA indicates a network attack vector with critical impact across all confidentiality, integrity, and availability metrics. The issue is addressed in Android 17 with a security patch level of 2026-07-01 or later.
Affected products
- Google Android 17
Timeline
- 2026-06-16: advisory: Android 17 Security Release Notes published
- 2026-06-17: disclosed: CVE published to NVD