Junglewise Threat Intelligence

CVE-2026-28616: Android Setup Wizard network spoofing via confused deputy

CVE-2026-28616 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Android's Setup Wizard component contains a flaw that allows a local attacker to force a device to connect to a malicious network through a confused deputy attack. This could enable privilege escalation on the affected device without requiring the attacker to have special permissions or user interaction. An attacker with local access could gain elevated system-level permissions.

Technical details

The vulnerability is a confused deputy (privilege escalation) flaw in the Android Setup Wizard component. An attacker with local access can exploit this to force the system to connect to a malicious network, leveraging the Setup Wizard's elevated privileges to escalate their own privilege level. The attack requires no additional execution privileges and no user interaction for exploitation. Patches are available in Android 14 and later versions through the 2026-09-05 security patch level.

Affected products

  • Google Android 14 and later

Timeline

  • 2026-09-08: disclosed
  • 2026-09-05: patched

References

Related threats