Junglewise Threat Intelligence

CVE-2026-28620: Android Framework permissions bypass leading to privilege escalation

CVE-2026-28620 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Android devices contain a vulnerability in the system Framework component that allows unauthorized access to restricted resources through a permissions bypass. An attacker can exploit this flaw without needing special privileges or user interaction to gain elevated access to the device, potentially compromising sensitive data and system functionality.

Technical details

This is a privilege escalation (EoP) vulnerability in the Android Framework component affecting the handling of URI permissions. The vulnerability exists in multiple locations where authorization checks are improperly enforced, allowing an attacker to bypass permission controls and gain local escalation of privilege. No additional execution privileges or user interaction are required for exploitation. The flaw affects Android 16, 16-qpr2, and 17. Security patches have been released to the Android Open Source Project (AOSP) and are available in the 2026-09-05 security patch level.

Affected products

  • Google Android 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed
  • 2026-09-05: patched

References

Related threats