Description
In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

A flaw in the onCreate routine of InstallLaunch.kt can display a misleading user interface that may be leveraged by tap‑jacking or overlay attacks. The vulnerability can allow a local adversary to execute privileged actions without obtaining additional code‑execution permissions or requiring the user to take any explicit action. The weakness, identified as CWE‑601, enables malicious manipulation of the interface that can elevate the attacker’s privileges on the device.

Affected Systems

Android devices that include the vulnerable InstallLaunch component are affected. The specific build version is not provided, so a broad range of current Android releases may be impacted until the fix is applied.

Risk and Exploitability

The severity score of 7.8 indicates a high potential impact, while the EPSS value of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, implying no large‑scale attacks have been documented. Nevertheless, the low barrier to exploitation—only local presence of a malicious app with overlay permissions—is sufficient reason for swift remediation.

Generated by OpenCVE AI on September 11, 2026 at 05:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch issued by Google, which resolves the InstallLaunch UI issue.
  • If a patch is not yet available, revoke or disable the overlay permission for untrusted applications to block malicious overlays from manipulating the interface.
  • Avoid installing applications from unknown or unverified sources, especially those that ask for system‑level or overlay permissions.
  • Apply device‑level restrictions that prevent apps from drawing over other applications, thereby eliminating secondary interfaces that could facilitate tap‑jacking.

Generated by OpenCVE AI on September 11, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Fri, 11 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via UI Misleading Attack on Android InstallLaunch

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Tapjacking-Enabled UI Misleading in Android Install Launch
Weaknesses CWE-639
CWE-640

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Tapjacking-Enabled UI Misleading in Android Install Launch
Weaknesses CWE-639
CWE-640

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:05:26.154Z

Reserved: 2026-03-02T19:10:53.530Z

Link: CVE-2026-28572

cve-icon Vulnrichment

Updated: 2026-09-10T15:05:21.500Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:51.277

Modified: 2026-09-15T14:30:10.153

Link: CVE-2026-28572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:00:10Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')