Junglewise Threat Intelligence

CVE-2026-28615: Google Android Telecom permissions bypass in phone call initiation

CVE-2026-28615 · Severity: info · CVSS 10 · Published 2026-06-17

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android Telecom component allows an unauthorized application to initiate phone calls without the required user permissions. This could lead to unauthorized communication or financial costs from premium-rate calls without the user's knowledge or interaction. The issue affects devices running Android 17 and represents a significant bypass of standard security controls.

Technical details

A vulnerability classified as Missing Authorization (CWE-862) exists within the Android Telecom subsystem. The flaw allows a local malicious application to bypass permission checks to initiate outgoing phone calls. Exploitation does not require any specific execution privileges or user interaction, effectively resulting in a local escalation of privilege (EoP). While the CNA provided a CVSS 4.0 score of 10.0 with a network attack vector, the technical description specifically identifies this as a local escalation of privilege. The issue is addressed in the Android 17 security release with a patch level of 2026-07-01 or later.

Affected products

  • Google Android 17

Timeline

  • 2026-06-16: advisory: Android 17 Security Release Notes published
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats