• PoC PUBLIC

CVE-2026-49881: local privilege escalation in Google Android

Local attackers can escalate privileges on Android via a logic error in InCallController's serviceClassExists, enabling arbitrary code execution; see CVE-2026-49881. The flaw affects Android branch 17.x (17) and can be exploited from a local process with low privileges; no user interaction is required for exploitation. An attacker only needs local access to the device to trigger the vulnerability and gain higher privileges.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00101
CWE
CWE-693
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Fix this urgently: public exploit code exists and the bug allows local arbitrary code execution without user interaction, so prioritize mitigation for Android 17 devices reachable to untrusted local apps.

What is CVE-2026-49881?

Local attackers can escalate privileges on Android via a logic error in InCallController's serviceClassExists, enabling arbitrary code execution; see CVE-2026-49881. The flaw affects Android branch 17.x (17) and can be exploited from a local process with low privileges; no user interaction is required for exploitation. An attacker only needs local access to the device to trigger the vulnerability and gain higher privileges.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Android are affected?

BRANCHAFFECTEDFIXED
17.x17

Is CVE-2026-49881 being exploited?

Public exploit code is available.

How to fix CVE-2026-49881

  1. Limit local exposure by restricting installation of untrusted apps and enabling Play Protect or equivalent on affected devices.
  2. Apply vendor guidance and updates as soon as a patch is released for Android 17.x.
  3. Monitor device behavior and logs for signs of privilege escalation and unexpected background services or processes.
  4. Harden device configuration: enforce app sandboxing policies, use device management controls to block unknown apps, and revoke unneeded local privileges.

Frequently asked questions

Is CVE-2026-49881 being actively exploited?

Public exploit code is available for CVE-2026-49881.

Which Android versions are affected by CVE-2026-49881?

Android branch 17.x (version 17) is listed as affected by CVE-2026-49881.

Is there a patch for CVE-2026-49881?

A fixed version is not listed for CVE-2026-49881; follow vendor guidance and apply updates when Google releases a patch for Android 17.x.

Does CVE-2026-49881 require authentication?

CVE-2026-49881 can be exploited locally without user interaction or additional authentication, but an attacker requires local code execution on the device to trigger it.

References