{"api_version":"1","generated_at":"2026-09-13T23:28:07+00:00","cve":"CVE-2026-28593","urls":{"html":"https://cve.report/CVE-2026-28593","api":"https://cve.report/api/cve/CVE-2026-28593.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-28593","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-28593"},"summary":{"title":"CVE-2026-28593","description":"In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","state":"PUBLISHED","assigner":"google_android","published_at":"2026-09-08 19:17:52","updated_at":"2026-09-10 16:17:10"},"problem_types":["CWE-356","Elevation of privilege","CWE-356 CWE-356 Product UI does not Warn User of Unsafe Actions"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-09-01","name":"https://source.android.com/docs/security/bulletin/2026/2026-09-01","refsource":"security@android.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-28593","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28593","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Google","product":"Android","version":"affected 17","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 16-qpr2","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 16","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 15","platforms":[]},{"source":"CNA","vendor":"Google","product":"Android","version":"affected 14","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"28593","cve":"CVE-2026-28593","epss":"0.000780000","percentile":"0.001430000","score_date":"2026-09-12","updated_at":"2026-09-13 00:08:19"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-28593","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-10T03:57:02.435045Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-356","description":"CWE-356 Product UI does not Warn User of Unsafe Actions","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-10T15:10:28.698Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Android","vendor":"Google","versions":[{"status":"affected","version":"17"},{"status":"affected","version":"16-qpr2"},{"status":"affected","version":"16"},{"status":"affected","version":"15"},{"status":"affected","version":"14"}]}],"descriptions":[{"lang":"en","value":"In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."}],"problemTypes":[{"descriptions":[{"description":"Elevation of privilege","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T18:04:43.372Z","orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android"},"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-09-01"}],"x_generator":{"engine":"cvelib 1.7.1"}}},"cveMetadata":{"assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","assignerShortName":"google_android","cveId":"CVE-2026-28593","datePublished":"2026-09-08T18:04:43.372Z","dateReserved":"2026-03-02T19:11:02.945Z","dateUpdated":"2026-09-10T15:10:28.698Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 19:17:52","lastModifiedDate":"2026-09-10 16:17:10","problem_types":["CWE-356","Elevation of privilege","CWE-356 CWE-356 Product UI does not Warn User of Unsafe Actions"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-10T03:57:02.435045Z","id":"CVE-2026-28593","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"28593","Ordinal":"1","Title":"CVE-2026-28593","CVE":"CVE-2026-28593","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"28593","Ordinal":"1","NoteData":"In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","Type":"Description","Title":"CVE-2026-28593"}]}}}