CVE-2026-28640None▾ SunlitIn checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privile…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-28648NoneIn Settings, there is a possible permission bypass due to a confused deputy
CVE-2026-28647NoneIn updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code
CVE-2026-28641NoneIn shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code
CVE-2026-28625NoneIn multiple locations, there is a possible permission bypass due to a logic error in the code
CVE-2026-58880High· 7.0In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition
CVE-2026-58865High· 7.5In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check