Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-28634

CVE-2026-28634: Android PhoneInterfaceManager Privilege Escalation

CVE-2026-28634 is a privilege escalation flaw in Android PhoneInterfaceManager that allows unauthorized USSD requests without permission. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-28634 Overview

CVE-2026-28634 is a local privilege escalation vulnerability in the Android handleUssdRequest method of PhoneInterfaceManager.java. A logic error in the permission check allows a local application to send an Unstructured Supplementary Service Data (USSD) request without holding the required permission. Exploitation requires no user interaction and no additional execution privileges beyond those already granted to a local app. The issue is classified under [CWE-693] Protection Mechanism Failure and was disclosed in the Android Security Bulletin September 2026.

Critical Impact

A local unprivileged app can issue USSD codes to the carrier network, enabling call forwarding, balance manipulation, or account changes without the user's knowledge.

Affected Products

  • Android Open Source Project (AOSP) telephony framework
  • Devices running affected Android releases prior to the September 2026 security patch level
  • OEM Android builds that incorporate the unpatched PhoneInterfaceManager.java

Discovery Timeline

  • 2026-09-08 - CVE-2026-28634 published to the National Vulnerability Database (NVD)
  • 2026-09-01 - Fix included in the Android Security Bulletin for September 2026
  • 2026-09-10 - Last updated in the NVD database

Technical Details for CVE-2026-28634

Vulnerability Analysis

The flaw resides in the handleUssdRequest method of PhoneInterfaceManager.java, a core component of the Android telephony framework. USSD is a GSM protocol used to interact with a mobile network operator's services, such as checking balance, activating call forwarding, or provisioning subscriber options. Android normally gates USSD dispatch behind the CALL_PHONE permission and additional caller checks.

Due to a logic error in the permission enforcement path, the method dispatches USSD requests to the underlying radio interface layer without verifying that the caller holds the required permission. A locally installed application can therefore issue arbitrary USSD codes as if it were a privileged system component.

Root Cause

The root cause is a Protection Mechanism Failure [CWE-693]. The code contains a permission check whose control flow does not correctly guard the sensitive operation. The check is either bypassable through a code path that reaches the USSD dispatch without evaluating it, or the check evaluates a condition that does not reflect the caller's actual privilege state.

Attack Vector

Exploitation is local and requires only that a malicious application be installed on the device. No user interaction is required. The attacker invokes the exposed telephony interface path that reaches handleUssdRequest, supplying an arbitrary USSD string. The framework then forwards the request to the carrier, which may execute account-level operations such as enabling unconditional call forwarding, transferring prepaid balance, or subscribing the victim to premium services. The technical details are documented in the Android Security Bulletin September 2026.

No public proof-of-concept exploit has been observed. Refer to the vendor advisory for the specific class and method-level fix.

Detection Methods for CVE-2026-28634

Indicators of Compromise

  • Unexpected USSD dialog activity or carrier-side notifications about call forwarding changes, subscription activations, or balance transfers
  • Installed applications that request telephony-related interfaces but do not hold the CALL_PHONE permission in their manifest
  • Anomalous invocations of telephony service methods originating from third-party UIDs in logcat telephony logs

Detection Strategies

  • Audit application behavior for calls to ITelephony interfaces from packages that lack declared telephony permissions
  • Correlate device telephony logs with carrier billing or provisioning events to identify unauthorized USSD dispatch
  • Use mobile threat defense tooling to flag apps invoking hidden or reflective telephony APIs

Monitoring Recommendations

  • Enroll devices in a Mobile Device Management (MDM) platform and enforce reporting of security patch level
  • Monitor carrier account changes such as call forwarding, roaming settings, and premium SMS subscriptions for unexpected modifications
  • Review logcat telephony subsystem output on managed devices for USSD activity from non-system UIDs

How to Mitigate CVE-2026-28634

Immediate Actions Required

  • Apply the September 2026 Android security patch level or later on all affected devices
  • Inventory installed applications and remove untrusted or sideloaded apps that request telephony-adjacent capabilities
  • Contact the mobile carrier to review and reverse any unauthorized call forwarding or subscription changes

Patch Information

The fix is included in the Android Security Bulletin for September 2026. Devices reporting a security patch level of 2026-09-01 or later contain the corrected handleUssdRequest permission enforcement in PhoneInterfaceManager.java. Consult the Android Security Bulletin September 2026 for the associated AOSP patch reference and OEM guidance.

Workarounds

  • Restrict installation of apps to Google Play or another vetted enterprise store until the patch is deployed
  • Disable installation from unknown sources on managed devices through MDM policy
  • On carrier accounts, set a call-forwarding PIN or block outbound premium services where the carrier supports it
bash
# Verify the Android security patch level on a connected device
adb shell getprop ro.build.version.security_patch
# Expected output for remediated devices: 2026-09-01 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.