Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-28659: Android XR Blobstore lets apps read other apps' files

CVE-2026-28659 · published 17 days ago
Summary

The Blobstore part of Android XR does not verify who is allowed to access stored files. Because of this, a malicious app could open and read files that belong to other apps without any user action, potentially exposing private data or increasing its own rights on the device. Install any available Android XR updates or security patches and avoid installing apps from untrusted sources.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
google android xr 14
google android_xr 14
cpe:2.3:o:google:android_xr:14:*:*:*:*:*:*:*
Original advisory text
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity
10.0 Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published8 Sep 2026
Updated25 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-28659 · MITRE
Track software like this
Free during beta