Junglewise Threat Intelligence

CVE-2026-58874: Android Framework privilege escalation in SmsController

CVE-2026-58874 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Google Android. Vendors: Google.

Executive brief

Android's system SMS handling component (SmsController) contains a missing permission check that allows local applications to escalate their privileges. An attacker with a basic app installed on an Android device can exploit this without needing any special access or user interaction, potentially gaining elevated system capabilities.

Technical details

This vulnerability is a privilege escalation (EoP) in multiple functions of SmsController.java due to missing permission validation. The root cause is insufficient authorization checks in the Framework component's SMS handling logic. The attack vector is local: a malicious application can call vulnerable SmsController functions to bypass permission restrictions and gain elevated privileges without requiring additional execution privileges or user interaction. An attacker can achieve local escalation of privilege, potentially gaining access to protected SMS operations or system functionality. Patches are available in Android versions 14, 15, 16, 16-qpr2, and 17 as part of the 2026-09-01 security patch level.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-09-08: disclosed
  • 2026-09-01: patched: Security patch level 2026-09-01 or later

References

Related threats