In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

Thu, 10 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Missing Permission Check in Android XR MicroXR Blobstore Enables Local Privilege Escalation

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Local Privilege Escalation in MicroXR Blobstore
Weaknesses CWE-284

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Wed, 09 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Missing Permission Check Allows Local Privilege Escalation in MicroXR Blobstore
Weaknesses CWE-284

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2026-09-08T19:20:33.261Z

Updated: 2026-09-09T20:37:00.386Z

Reserved: 2026-03-02T19:11:19.581Z

Link: CVE-2026-28659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T20:17:32.957

Modified: 2026-09-09T21:17:01.867

Link: CVE-2026-28659

cve-icon Redhat

No data.