Impact
A logic error in the areBackgroundActivityStartsAllowed function of BackgroundLaunchProcessController.java permits activities to be launched in the background without the normal restrictions, which is a logic flaw. Missing proper authorization control (CWE-693) further enables this behavior. The flaw does not require user interaction and allows a user to execute code with their own privileges for the duration of the activity.
Affected Systems
The vulnerability affects the Android operating system supplied by Google. No specific product versions are listed, so any Android installation may be susceptible until a vendor patch is released.
Risk and Exploitability
The CVSS score is 7.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Still, the ability to launch background activities without user interaction and to gain user‑level execution rights represents a high‑risk local privilege escalation path. An attacker with any local user account could trigger the flaw, potentially running code in the background with the privileges of that patch keeps the risk significant until a vendor fix is applied.
OpenCVE Enrichment