In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28640
NONE
Обновлено 6 октября 2026
Google
google:android
Сводка
CVE ID
CVE-2026-28640
Опубликовано
5 октября, 2026
Поставщик
Google
Уровень угрозы
NONE
Ущерб
Минимальное воздействие
Ссылка
Перейти к источнику