DIRAS TAKE
Fix this urgently: public exploit code exists and the bug allows local arbitrary code execution without user interaction, so prioritize mitigation for Android 17 devices reachable to untrusted local apps.
What is CVE-2026-49881?
Local attackers can escalate privileges on Android via a logic error in InCallController's serviceClassExists, enabling arbitrary code execution; see CVE-2026-49881. The flaw affects Android branch 17.x (17) and can be exploited from a local process with low privileges; no user interaction is required for exploitation. An attacker only needs local access to the device to trigger the vulnerability and gain higher privileges.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 17.x | 17 |
Is CVE-2026-49881 being exploited?
Public exploit code is available.
How to fix CVE-2026-49881
- Limit local exposure by restricting installation of untrusted apps and enabling Play Protect or equivalent on affected devices.
- Apply vendor guidance and updates as soon as a patch is released for Android 17.x.
- Monitor device behavior and logs for signs of privilege escalation and unexpected background services or processes.
- Harden device configuration: enforce app sandboxing policies, use device management controls to block unknown apps, and revoke unneeded local privileges.
Frequently asked questions
Is CVE-2026-49881 being actively exploited?
Public exploit code is available for CVE-2026-49881.
Which Android versions are affected by CVE-2026-49881?
Android branch 17.x (version 17) is listed as affected by CVE-2026-49881.
Is there a patch for CVE-2026-49881?
A fixed version is not listed for CVE-2026-49881; follow vendor guidance and apply updates when Google releases a patch for Android 17.x.
Does CVE-2026-49881 require authentication?
CVE-2026-49881 can be exploited locally without user interaction or additional authentication, but an attacker requires local code execution on the device to trigger it.
References
- nvd.nist.gov/vuln/detail/CVE-2026-49881
- cve.org/CVERecord?id=CVE-2026-49881
- source.android.com/docs/security/bulletin/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026