CVEFinder.io

CVE-2026-28573

🔶 medium
🔍 Scan for this CVE
Summary

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS Score
5.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2026-06-18
First Seen: 2026-06-25
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 31.8% of all 342,933 vulnerabilities in our database.

#234,014
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jun 18, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-06-22
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 2

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-48617 ⚠️ high 7.8 0.1 In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. ... 2026-06-17
CVE-2025-48640 ⚠️ high 8.0 0.1 In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T... 2026-06-17
CVE-2025-48643 ⚠️ high 7.8 0.1 In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local... 2026-06-17
CVE-2026-0019 ⚠️ high 7.8 0.1 In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead t... 2026-06-17
CVE-2026-0063 ⚠️ high 7.8 0.2 In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a lo... 2026-06-17
CVE-2026-0068 ⚠️ high 7.8 0.1 In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed ... 2026-06-17
These CVEs affect the same products