CVE-2026-28611: Security vulnerability
Published Sep 8, 2026
·Updated
In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs local access on the device. No additional execution privileges and no user interaction are required.
2
What is the potential impact of successful exploitation?
Successful exploitation could enable silent payment session hijacking and result in local escalation of privilege.