CVE-2026-28640: Input Validation
Published Oct 5, 2026
·Updated
In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 5, 2026
CVE Published
via MITRE·06:39 PM
Data Sourced
via MITRE·06:39 PM
DescriptionWeakness
Frequently Asked Questions
1
Are affected Android versions identified in the available record?
No affected Android versions are specified in the provided data. Teams will need to verify applicability using the referenced Android security bulletin or their device/vendor update information.
2
Is vendor guidance referenced for this issue?
Yes. The record references a Source Android security bulletin dated 2026-10-01.