Description
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a background activity to be launched in a way that bypasses the normal security checks, effectively turning a lower-privilege component into an unintended authority. This confused-deputy flaw enables an attacker to acquire local privileges on the device without executing any additional code or engaging a user. The impact is a direct escalation from ordinary user privileges to privileged system level, allowing an attacker to modify or delete system data, install software, or perform other privileged actions. The flaw is present in Google's Android operating system across all builds that include the affected functions. No specific Android releases or build variants are enumerated in the advisory, so the vulnerability applies broadly to current Android devices that have addressing the issue. The CVSS score of 7.8 classifies the issue as high severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been commonly exploited. Nevertheless, the lack of required user interaction and the local nature of the attack vector mean that a privileged local actor could abuse the flaw to gain administrative rights. Until an official patch is delivered, the risk remains significant for all affected devices.

Affected Systems

All Google Android devices containing the vulnerable background activity launch code are affected. The advisory does not specify particular release versions from Google, so devices running any current Android OS release that has not yet been updated to the forthcoming security bulletin may be at risk.

Risk and Exploitability

Given the high CVSS score and the fact that the flaw does not require user interaction, the exposure is substantial. The low EPSS score suggests that active exploitation may be limited at this time, but the vulnerability’s potential to grant local privileges to a local adversary makes it a critical concern until the vendor releases a fix. The attack vector is local, with an attacker able to trigger the background launch from an app or process that lacks sufficient permission checks. The lack of additional execution privileges or user interaction reduces the complexity of exploitation, increasing the probability that a local attacker could successfully gain administrative capabilities.

Generated by OpenCVE AI on September 11, 2026 at 05:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update released by the device manufacturer as soon as it becomes available.
  • Configure device policies or use device administration tools to restrict or audit background activity launches, ensuring only trusted system components can initiate them.
  • Disable or limit background activity execution through system settings or third-party policy apps to reduce the attack surface.\n

Generated by OpenCVE AI on September 11, 2026 at 05:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Background Activity Launch Bypass Leading to Local Privilege Escalation in Android
Weaknesses CWE-269
CWE-272

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Background Activity Launch Bypass Leading to Local Privilege Escalation in Android
Weaknesses CWE-269
CWE-272

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:09:36.074Z

Reserved: 2026-03-02T19:11:06.138Z

Link: CVE-2026-28607

cve-icon Vulnrichment

Updated: 2026-09-10T15:09:31.812Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:52.920

Modified: 2026-09-15T14:28:24.783

Link: CVE-2026-28607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:15:17Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')