
VulDB 🛡@vuldb
There is a new vulnerability with elevated criticality in Google Android (CVE-2026-28640) vuldb.com/vuln/413731
00000100
2.3K followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

There is a new vulnerability with elevated criticality in Google Android (CVE-2026-28640) vuldb.com/vuln/413731