Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-28659: Android XR Blobstore lets apps read other apps' files
CVE-2026-28659 · published 17 days ago
Summary
The Blobstore part of Android XR does not verify who is allowed to access stored files. Because of this, a malicious app could open and read files that belong to other apps without any user action, potentially exposing private data or increasing its own rights on the device. Install any available Android XR updates or security patches and avoid installing apps from untrusted sources.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| android xr | 14 | |
| android_xr |
14 cpe:2.3:o:google:android_xr:14:*:*:*:*:*:*:* |
Original advisory text
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...
In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Severity
10.0
Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published8 Sep 2026
Updated25 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta