Junglewise Threat Intelligence

CVE-2026-28659: MicroXR Blobstore privilege escalation via missing permission check

CVE-2026-28659 · Severity: high · CVSS 7.8 · Published 2026-09-08

Vendors: Google.

Executive brief

MicroXR Blobstore is a file storage component in the Android XR platform. A missing permission check allows any local application to access files belonging to other applications, potentially leading to theft of sensitive data or exposure of credentials. This escalation requires no special privileges or user interaction to exploit.

Technical details

The vulnerability is a local privilege escalation (EoP) in MicroXR Blobstore caused by inadequate permission validation when accessing stored files. The flaw allows an unprivileged local application to bypass access controls and read or manipulate files belonging to other applications without authorization. Attack surface is limited to local network access (adjacent or local) and requires no additional execution privileges; user interaction is not needed. An attacker can achieve unauthorized access to cross-app data, compromising confidentiality and integrity. The Android XR Security Bulletin for September 2026 indicates patches are available in security patch level 2026-09-01 or later; affected AOSP versions include Android 14.

Affected products

  • Google Android XR 14
  • Google MicroXR Blobstore

Timeline

  • 2026-09-08: disclosed: CVE-2026-28659 published in Android XR Security Bulletin
  • 2026-09-01: patched: Fix included in security patch level 2026-09-01 or later

References

Related threats