Executive brief
Android's Setup Wizard component contains a flaw that allows a local attacker to force a device to connect to a malicious network through a confused deputy attack. This could enable privilege escalation on the affected device without requiring the attacker to have special permissions or user interaction. An attacker with local access could gain elevated system-level permissions.
Technical details
The vulnerability is a confused deputy (privilege escalation) flaw in the Android Setup Wizard component. An attacker with local access can exploit this to force the system to connect to a malicious network, leveraging the Setup Wizard's elevated privileges to escalate their own privilege level. The attack requires no additional execution privileges and no user interaction for exploitation. Patches are available in Android 14 and later versions through the 2026-09-05 security patch level.
Affected products
- Google Android 14 and later
Timeline
- 2026-09-08: disclosed
- 2026-09-05: patched