Junglewise Threat Intelligence

CVE-2026-28581: Google Android logic error in CallIntentProcessor

CVE-2026-28581 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android System component allows for the unauthorized initiation of emergency calls. This could potentially be used to disrupt device functionality or trigger emergency services without user consent. The issue affects various versions of the Android operating system and does not require user interaction to exploit.

Technical details

A logic error exists within the 'fixInitiatingUserIfNecessary' method of 'CallIntentProcessor.java' in the Android System component. This vulnerability allows a local attacker to bypass intended restrictions and initiate emergency calls. The exploit requires no additional execution privileges and zero user interaction. The vulnerability is classified as an Information Disclosure (ID) type in the Android bulletin, though the description suggests a logic error leading to unauthorized action. It affects Android versions 14, 15, 16, and 16-qpr2. A patch is available as part of the June 2026 Android Security Bulletin.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin
  • 2026-06-01: patched: Security patch levels of 2026-06-05 or later address this issue

References

Related threats