DIRAS TAKE
Fix urgently: this flaw allows escalation without user interaction and carries a critical CVSS 9.8 rating. Prioritize mitigations for internet- or Bluetooth-exposed devices until Google issues a patch.
What is CVE-2026-28606?
A remote attacker can bypass Bluetooth pairing and escalate privileges on Android devices (CVE-2026-28606). The issue stems from a logic error in AdapterService.java that can skip the pairing process, allowing privilege escalation without user consent or additional execution privileges and without user interaction. Affected Android branches include 17, 16 (including 16-qpr2), and 15. Exploitation does not require the target user to click anything or to authenticate. The weakness is classified as CWE-287 (Improper Authentication).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 17.x | 17 | |
| 16.x | 16-qpr2 | |
| 16.x | 16 | |
| 15.x | 15 |
Is CVE-2026-28606 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-28606
- Follow vendor guidance and install official updates when Google releases a patch.
- Disable Bluetooth or restrict Bluetooth radios on devices that do not require it.
- Limit device exposure by enforcing network and interface segmentation for Bluetooth-capable endpoints.
- Monitor device logs for unexpected bonding or pairing state changes and investigate anomalies.
Frequently asked questions
Is CVE-2026-28606 being actively exploited?
There are no public reports of exploitation of CVE-2026-28606 as of 2026-09-29.
Which Android versions are affected by CVE-2026-28606?
Android branches listed as affected are 17, 16 (including 16-qpr2), and 15.
Is there a patch for CVE-2026-28606?
No fixed versions are listed; no patch is available as of 2026-09-29, so apply mitigations and install vendor updates when released.
Does CVE-2026-28606 require authentication?
No; the vulnerability allows pairing to be skipped and privilege escalation without user interaction or authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-28606
- cve.org/CVERecord?id=CVE-2026-28606
- source.android.com/docs/security/bulletin/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026