HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-28573Published Modified CNA google_android

CVE-2026-28573: In AndroidManifest

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Metrics

CVSS v4.0
10.0
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a persistent denial-of-service vulnerability in Google Android (versions 14 and 16) caused by a missing permission check in AndroidManifest.xml. Despite the description noting local impact, the CVSS v4.0 vector is rated 10.0 (Critical) with network-reachable, no-authentication, no-interaction scope across both vulnerable and subsequent system components. Successful exploitation allows an attacker to permanently disrupt the affected Android service, with full confidentiality, integrity, and availability impact scored across system scope. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Google publishes an upstream fix.

HarborGuard Coverage

Detection

Detection of CVE-2026-28573 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built Android-derived or AOSP-based container images in connected registries and CI pipelines.

Available
Triage

Triage is available using the CVSS v4.0 score of 10.0 (Critical), weighted against each customer organization's compliance policy to prioritize routing; findings are delivered to the appropriate team inbox within each customer environment automatically.

Available
Patch

No upstream fix versions have been published for CVE-2026-28573 as of the record date. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Google publishes a remediated release for Android 14 or 16.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The CVSS v4.0 vector specifies AV:N, meaning the attacker must be able to reach the affected service over the network to trigger the vulnerability.

  • AuthenticationNot required

    PR:N in the vector indicates no account or privilege level is needed before launching the attack.

  • Victim interactionNot required

    UI:N confirms no user action such as clicking a link or opening a file is required for exploitation.

  • Attack complexityDetail

    AC:L with AT:N means the exploit is reliable and requires no special conditions, race timing, or environmental configuration to succeed.

Blast Radius

  • An attacker can permanently crash or disable the targeted Android service, requiring a device reset or manual intervention to restore normal operation.
  • Full confidentiality impact (VC:H, SC:H) means an attacker reads protected data stored by the affected service, including any credentials or session material accessible to that process.
  • Full integrity impact (VI:H, SI:H) means an attacker modifies persisted data or system state managed by the affected component.
  • Full availability impact (VA:H, SA:H) means the attacker renders both the directly affected component and dependent system services completely unresponsive.

How HarborGuard Handles This

Available on HarborGuard: because no upstream patch exists for CVE-2026-28573, HarborGuard monitors the Google Android advisory on every ingest cycle and will surface a patched-image rebuild the moment a fix version is published. In the meantime, customers can apply compensating controls within HarborGuard-managed environments: network policy rules can be configured to restrict inbound access to exposed Android service endpoints, egress filtering can limit lateral movement if a container-hosted component is compromised, and feature-flag or capability gating can be used to disable the vulnerable manifest-registered component where the application architecture permits. Customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads automatically once an upstream fix becomes available, with no manual intervention required.

See how HarborGuard automates this
Affected packages
  • Google / Android
    14 · 16
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H