Executive brief
Android's system SMS handling component (SmsController) contains a missing permission check that allows local applications to escalate their privileges. An attacker with a basic app installed on an Android device can exploit this without needing any special access or user interaction, potentially gaining elevated system capabilities.
Technical details
This vulnerability is a privilege escalation (EoP) in multiple functions of SmsController.java due to missing permission validation. The root cause is insufficient authorization checks in the Framework component's SMS handling logic. The attack vector is local: a malicious application can call vulnerable SmsController functions to bypass permission restrictions and gain elevated privileges without requiring additional execution privileges or user interaction. An attacker can achieve local escalation of privilege, potentially gaining access to protected SMS operations or system functionality. Patches are available in Android versions 14, 15, 16, 16-qpr2, and 17 as part of the 2026-09-01 security patch level.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-09-08: disclosed
- 2026-09-01: patched: Security patch level 2026-09-01 or later