securityonline.info 10 Sept 2026, 00:00 UTC

Android 17 Exploit Chain Gives Untrusted Apps Kernel Control

Android 17 Exploit Chain Gives Untrusted Apps Kernel Control
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS have disclosed the LSPromise exploit chain, which they say can take an untrusted local Android app through to full kernel control. The chain affects the initial official release of Android 17 and was successfully tested on a Pixel 10; it did not work on a Pixel 6a. No exploitation has been confirmed, but proof-of-concept code and technical details have reportedly been made public. Devices using 6.1.xxx-android14 kernel trees may also be exposed to the chain’s kernel component.

The chain combines three vulnerabilities: Android Telecom logic flaw CVE-2026-49881, and the kernel issues CVE-2026-43284 (“DirtyFrag”) and CVE-2026-43500. The first flaw can allow code to be loaded from an arbitrary app and executed in the privileged system_server process. The researchers then describe using Java reflection and a network-stack process to load native code before exploiting the kernel flaw, modifying system libraries and loading an unauthorised kernel module.

This can disable SELinux protections and provide root-level control, while bypassing mitigations including KASLR and MTE. CVE-2026-43284 is rated 8.8 (High) under CVSSv3, while CVE-2026-43500 is rated 7.8; CVE-2026-49881 is awaiting analysis. Google fixed the userspace flaw in September 2026. Users should install the latest security update supplied by their device manufacturer; the article says no other mitigation is available.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline