PatchSiren

Google CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Google CVE published 2026-09-08

CVE-2026-28659

CVE-2026-28659 is a critical vulnerability in MicroXR Blobstore that allows local escalation of privilege due to a missing permission check. This issue requires immediate attention from Android XR system administrators and security teams. The vulnerability has a CVSS score of 10 and can lead to unauthorized access to sensitive data. It is essential to review and apply the vendor advisory, conduct inventor [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-55285

CVE-2026-55285 is a high-severity vulnerability in Google Android, allowing for local escalation of privilege with no additional execution privileges needed. The vulnerability is due to a missing bounds check in openLogicalChannel of multiple files, which could lead to an out-of-bounds write. This vulnerability affects Google Android systems and devices, particularly those handling sensitive data or expos [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-55277

A high-severity CVE-2026-55277 vulnerability exists in Google Android due to a missing bounds check in RoutingManager.cpp, potentially leading to remote code execution with proximal/adjacent access and no additional privileges required. This issue affects Android versions 16.0 and 17.0, with defenders needing to assess exposure and prioritize patching and compensating controls. The vulnerability's CVSS sc [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-55273

CVE-2026-55273 is a high-severity vulnerability in Google Android, with a CVSS score of 7.8. The vulnerability is due to improper input validation in the AppendCommentLine function of AnnotationProcessor.cpp, which could lead to local escalation of privilege. The CVE record was published on 2026-09-08T19:18:01.500Z and was last modified on 2026-09-25T13:10:59.690Z. The NVD entry is currently Analyzed.

HIGH Google CVE published 2026-09-08

CVE-2026-49887

A high-severity CVE-2026-49887 vulnerability exists in Google Android, allowing for local escalation of privilege due to a permissions bypass in maybeRemoveInvalidInstallerPackageName of InstallRepository.kt. This issue requires no additional execution privileges and does not need user interaction for exploitation. The vulnerability affects Google Android versions 16.0 and 17.0, and defenders should asses [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-49884

A high-severity CVE-2026-49884 vulnerability exists in Google Android due to an out-of-bounds write issue in the rw_mfc_handle_read_op function of rw_mfc.cc. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability affects multiple Android versions, including 14.0, 15.0, 16.0, 16.0 qpr2, and 17.0. [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-49882

A memory safety issue due to a heap buffer overflow in rw_mfc_handle_read_op of rw_mfc.cc could lead to remote code execution with no additional execution privileges needed in Google Android versions 14.0, 15.0, 16.0, and 17.0. This vulnerability is particularly concerning as it can be exploited without user interaction, emphasizing the need for defenders to prioritize patching and monitoring. The affecte [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-49881

A logic error in the serviceClassExists function of InCallController.java could lead to local escalation of privilege with no additional execution privileges needed. This issue affects Android 17.0 systems, and defenders should prioritize verifying and applying patches from Google. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. The issue was publicly disclosed on 2026-09-08 and [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-49879

CVE-2026-49879 is a high-severity vulnerability in Google Android, with a CVSS score of 8.8. An integer overflow in multiple functions of rw_t3t.cc could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The CVE was published on 2026-09-08 and last modified on 2026-09-23.

HIGH Google CVE published 2026-09-08

CVE-2026-45531

A high-severity CVE-2026-45531 vulnerability exists in Google Android due to a possible out of bounds read via a heap buffer overflow in fsck.c. Local escalation of privilege is possible without additional execution privileges needed. User interaction is not required for exploitation. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Android system administrators and security teams shou [truncated]

LOW Google CVE published 2026-09-08

CVE-2026-28671

A race condition in MediaProvider.java could expose file contents, leading to local information disclosure without additional execution privileges needed. This vulnerability affects Android systems, particularly versions 14.0, 15.0, 16.0, and 17.0. Android developers, security teams, and administrators should assess exposure and apply patches from the vendor advisory. The vulnerability allows for local in [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28668

A logic error in the LimitRealloc function of malloc_limit.cpp could lead to a use-after-free vulnerability, allowing for local escalation of privilege without additional execution privileges needed. This vulnerability affects Android versions 14.0, 15.0, 16.0, and 17.0. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.8. Android system administrators, secur [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28666

CVE-2026-28666 is a Remote Persistent Denial of Service vulnerability in LocalImageResolver.java due to a DNG image rendering check bypass, potentially leading to remote escalation of privilege without additional execution privileges needed. User interaction is not required for exploitation. This vulnerability affects Google Android versions 14.0, 15.0, 16.0, 16.0 QPR2, and 17.0. Defenders should assess e [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28664

CVE-2026-28664 is a high-severity vulnerability in Google Android, allowing local escalation of privilege with no additional execution privileges needed. The issue lies in the WriteImageToDisk function of runtime_image.cc, where a logic error can lead to file tampering. This vulnerability can have significant impacts on the security of Google Android devices and versions. Defenders should assess exposure [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28663

CVE-2026-28663 is a high-severity vulnerability in Google Android, allowing local escalation of privilege with no additional execution privileges needed. The vulnerability exists in the buildIntentSenderForUser function of LauncherAppsService.java and can be exploited without user interaction. This vulnerability impacts Android developers, security teams, and administrators responsible for managing Androi [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28662

CVE-2026-28662 is a high-severity vulnerability in Google Android, potentially allowing proximal code execution. The vulnerability exists in the p2p_process_prov_disc_bootstrap_req function of p2p_pd.c, where a heap buffer overflow could occur, leading to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation.

LOW Google CVE published 2026-09-08

CVE-2026-28660

CVE-2026-28660 is a local information disclosure vulnerability in multiple Android files due to a logic error in the getAllSessions function. This could lead to local information disclosure with no additional execution privileges needed. The vulnerability has a CVSS score of 3.3 and is considered low severity. User interaction is not needed for exploitation. Defenders should assess exposure and prioritize [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28658

CVE-2026-28658 is a high-severity vulnerability in Google Android, allowing for local escalation of privilege with no additional execution privileges needed. The vulnerability is due to a logic error in the AccountsDb.java file. Android versions 14.0, 15.0, 16.0, and 17.0 are affected. This vulnerability could allow an attacker to gain elevated privileges on a device, potentially leading to further exploi [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28657

CVE-2026-28657 is a high-severity vulnerability in Google Android, allowing local escalation of privilege with no additional execution privileges needed. The issue arises from a possible unauthorized URI permission grant due to a confused deputy in AppWidgetConfigActivityProxy.java. User interaction is not required for exploitation. This vulnerability affects Android versions 16.0 and 17.0, and defenders [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28656

CVE-2026-28656 is a high-severity vulnerability in Google Android, allowing for local escalation of privilege through a tapjacking/overlay attack. The vulnerability is rated with a CVSS score of 7.3 and requires user interaction for exploitation. Affected versions include Android 14.0, 15.0, and 16.0. Defenders should prioritize verifying and applying patches for these versions to prevent potential escala [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28655

CVE-2026-28655 is a high-severity vulnerability in Google Android, allowing for local escalation of privilege with no additional execution privileges needed. The issue lies in multiple functions of RemoteViews.java, where a logic error enables a background activity launch bypass. User interaction is not required for exploitation. This vulnerability affects Android versions 14.0, 15.0, 16.0, and 17.0, and [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28653

CVE-2026-28653 is a high-severity vulnerability in Google Android, with a CVSS score of 7.8. An integer overflow in multiple functions of rw_t3t.cc could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation. This vulnerability affects Android versions 14.0, 15.0, 16.0, 16.0 qpr2, and 17.0. Defenders responsible for managing [truncated]

LOW Google CVE published 2026-09-08

CVE-2026-28652

A CVE record for a potential MITM vulnerability in RangingServiceImpl.java was published on 2026-09-08T19:17:55.747Z and last modified on 2026-09-15T14:06:34.023Z. The NVD entry is currently Analyzed. This vulnerability affects Android systems, particularly those with version 16.0 and 17.0, and could lead to remote information disclosure with no additional execution privileges needed. Defenders should ass [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28650

CVE-2026-28650 is a high-severity vulnerability in Google Android, with a CVSS score of 7.8. It allows for local escalation of privilege with no additional execution privileges needed, due to a logic error in the WindowState.java code. User interaction is not required for exploitation. This vulnerability affects Google Android systems, and defenders should prioritize assessing exposure and applying patche [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28644

CVE-2026-28644 is a high-severity vulnerability in the ActivityTaskManagerService.java of the Google Android operating system. The issue allows for a possible permission bypass due to a confused deputy, which could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.

HIGH Google CVE published 2026-09-08

CVE-2026-28642

CVE-2026-28642 debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T19:17:55.450Z and has not been modified since then. This HIGH-severity vulnerability in Android allows for local escalation of privilege. Android security teams should assess exposure and prioritize patching. The vulnerability is due to a logic error in the ActivityStarter.java code, allowing for a possi [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28639

A logic error in the rw_mfc_handle_read_op function of rw_mfc.cc could lead to a local escalation of privilege. This issue requires no additional execution privileges and user interaction is not needed for exploitation. The vulnerability affects Android system administrators and security teams, who should assess exposure and apply patches or updates provided by the vendor. The CVE record and NVD entry pro [truncated]

LOW Google CVE published 2026-09-08

CVE-2026-28638

A logic error in XmpDataParser.java could lead to local information disclosure with no additional execution privileges needed. This issue affects Android products using XmpDataParser.java. Defenders should assess exposure, verify data sanitization, and review affected versions for potential updates or patches. The CVE record and NVD entry provide details on the vulnerability. The logic error could allow u [truncated]

HIGH Google CVE published 2026-09-08

CVE-2026-28636

CVE-2026-28636 is a high-severity vulnerability in Google Android, allowing local escalation of privilege with no additional execution privileges needed. The vulnerability is due to a confused deputy in the setupLayout of PickActivity.java, which could lead to a bypass of the 'Install unknown apps' security restriction. This issue affects Google Android deployments, particularly those using affected versi [truncated]

MEDIUM Google CVE published 2026-09-08

CVE-2026-28633

A CVE record describes a possible persistent denial of service due to resource exhaustion in VoiceInteractionManagerService.java. The issue is rated as Medium with a CVSS score of 5.5. User interaction is not needed for exploitation. This CVE was published on 2026-09-08T19:17:54.987Z and was last modified on 2026-09-15T14:03:11.307Z. The vulnerability affects Android versions and could lead to a denial of [truncated]