Google Android: Three Medium-Severity Flaws Including Privilege Escalation Disclosed Together
Google disclosed three medium-severity Android vulnerabilities on October 5, 2026, including two permission bypass flaws and a denial of service bug.

Key findings
- Three medium-severity Android vulnerabilities disclosed by Google on October 5, 2026.
- Two vulnerabilities allow for local privilege escalation due to permission bypass flaws.
- One vulnerability causes a persistent denial of service due to improper input validation.
- Exploitation requires no user interaction and no additional privileges.
On October 5, 2026, Google disclosed three medium-severity vulnerabilities affecting its Android operating system. The vulnerabilities, all disclosed simultaneously, include a persistent denial of service and two distinct permission bypass flaws that could lead to local privilege escalation. These issues highlight potential weaknesses in input validation and permission handling within the Android framework.
Two of the vulnerabilities, CVE-2026-28648 and CVE-2026-28625, are related to permission bypass. CVE-2026-28648, found in Settings, stems from a confused deputy vulnerability, while CVE-2026-28625 arises from a logic error in multiple code locations. Both allow for local privilege escalation without requiring additional execution privileges.
The third vulnerability, CVE-2026-58834, is a persistent denial of service flaw located in the DevicePolicyManagerService.java file. It is caused by improper input validation and could lead to a local denial of service condition.
None of these vulnerabilities require user interaction for exploitation, making them potentially more dangerous for end-users. The simultaneous disclosure suggests a coordinated effort by Google's security team to address these issues. As of the disclosure, no specific patches or affected version ranges were detailed, but users are generally advised to keep their Android devices updated to the latest available security patches.
These vulnerabilities underscore the ongoing challenges in securing complex operating systems like Android, particularly concerning robust input validation and the intricate permission models that govern application behavior. Users should remain vigilant about applying security updates provided by Google to mitigate these risks.