Description
In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

A logic error in the areBackgroundActivityStartsAllowed function of BackgroundLaunchProcessController.java permits activities to be launched in the background without the normal restrictions, which is a logic flaw. Missing proper authorization control (CWE-693) further enables this behavior. The flaw does not require user interaction and allows a user to execute code with their own privileges for the duration of the activity.

Affected Systems

The vulnerability affects the Android operating system supplied by Google. No specific product versions are listed, so any Android installation may be susceptible until a vendor patch is released.

Risk and Exploitability

The CVSS score is 7.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Still, the ability to launch background activities without user interaction and to gain user‑level execution rights represents a high‑risk local privilege escalation path. An attacker with any local user account could trigger the flaw, potentially running code in the background with the privileges of that patch keeps the risk significant until a vendor fix is applied.

Generated by OpenCVE AI on September 11, 2026 at 05:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch once it is released by Google
  • Configure the device or application to disallow background activity launches by adjusting process and permission settings
  • Monitor system logs for unexpected background activity starts and investigate anomalies that may indicate exploitation

Generated by OpenCVE AI on September 11, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Thu, 10 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Android Background Activity Launch Logic Bug Allows Local Privilege Escalation
Weaknesses CWE-571

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Android Background Activity Launch Logic Bug Allows Local Privilege Escalation
Weaknesses CWE-571

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:02:10.680Z

Reserved: 2025-10-15T15:40:46.007Z

Link: CVE-2026-0065

cve-icon Vulnrichment

Updated: 2026-09-10T15:02:05.167Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:49.970

Modified: 2026-09-15T14:29:33.437

Link: CVE-2026-0065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:30:15Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure