GoogleCVE-2026-58691
Google Android: improper input validation
High8.4CVE-2026-58691 · Published Sep 15, 2026 · updated Sep 18, 2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Android Product | <= Android kernel | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-20
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Google Chrome: race condition | High8.3 | 153.0.8010.47 |
| Sep 15 | Google Chrome: race condition | Medium5.3 | 153.0.8010.47 |
| Sep 15 | Google Chrome: use after free | High8.8 | 153.0.8010.47 |
| Sep 15 | Google Chrome: integer overflow | Medium4.3 | 153.0.8010.47 |
| Sep 15 | Google Chrome: use after free | Low3.1 | 153.0.8010.47 |
| Sep 15 | Google Chrome: race condition | High8.3 | 153.0.8010.47 |