CVE-2026-56952: Medium severity Google Android vulnerability
Published Oct 6, 2026
·Updated
In platformmsghandlerinit of defaultmsghandlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 6, 2026
CVE Published
via MITRE·06:20 PM
Data Sourced
via MITRE·06:20 PM
DescriptionWeakness
Data Sourced
via NVD·07:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
Exploitation is local and requires System execution privileges. No user interaction is needed.
2
Which product is identified as affected?
The affected software is identified as Google Android from Google. No affected Android versions are specified in the available information.