Junglewise Threat Intelligence

CVE-2026-28586: Google Android permission bypass in AppOpsService

CVE-2026-28586 · Severity: info · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's AppOpsService could allow a malicious application to bypass security permission checks. This flaw enables the unauthorized access of sensitive information stored on the device without requiring any interaction from the user. Successful exploitation could lead to the disclosure of private data to unauthorized local apps.

Technical details

A vulnerability in Google Android's Framework component, specifically within multiple functions of AppOpsService.java, is caused by a missing permission check. This flaw allows a local attacker to bypass intended permission restrictions to access sensitive information. The attack does not require elevated execution privileges or user interaction. The issue affects Android versions 14, 15, 16, and 16-qpr2. A fix is available as part of the Android June 2026 security patch level (2026-06-05).

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats