Junglewise Threat Intelligence

CVE-2026-28580: Google Android Framework privilege escalation via incorrect bounds check

CVE-2026-28580 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A security vulnerability exists in the Android Framework, the core set of software components that provide essential services to mobile apps. An attacker could exploit this flaw to gain elevated system privileges on a device without needing any special permissions or user interaction. This could allow a malicious app to bypass security restrictions and access sensitive data or perform unauthorized actions.

Technical details

A vulnerability in the Google Android Framework component (specifically tracked as A-481967442) is caused by an incorrect bounds check across multiple functions. This flaw leads to a 'desync in persistence,' which can be leveraged by a local attacker to achieve escalation of privilege (EoP). The exploit requires no additional execution privileges and no user interaction. The issue affects Android versions 16 and 16-qpr2. Security patch levels of 2026-06-05 or later address this vulnerability.

Affected products

  • Google Android Framework 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: disclosed

References

Related threats