Description
In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Apply Update
AI Analysis

Impact

A logic error in the resolveActivity method of ActivityStarter.java allows malicious apps to redirect intents to system components, enabling an app to trigger privileged actions without the user’s knowledge, thereby providing a path to local elevation of privileges. The flaw can be used to compromise applications or system services by exploiting the trust granted to intent handlers.

Affected Systems

The vulnerability affects Google Android devices; the public advisory does not list specific OS versions, so any build that contains the vulnerable ActivityStarter code is potentially impacted until an official fix is released.

Risk and Exploitability

The exploit is local; an attacker who can install or execute code on the device can craft malicious. The EPSS score of <1% indicates a low probability of exploitation, and the CVSS score of 7.8 reflects high severity. Although not cataloged in CISA KEV, the potential for local privilege escalation makes the risk significant for affected devices.

Generated by OpenCVE AI on September 10, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that fixes the ActivityStarter intent redirection flaw
  • Disallow untrusted apps from sending implicit intents that target system components—use device security settings to limit intent‑handling permissions
  • Remove or block any installed applications known to misuse intent redirection techniques

Generated by OpenCVE AI on September 10, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Intent Redirection Vulnerability in Android Leading to Local Escalation of Privilege
Weaknesses CWE-264
CWE-380

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Intent Redirection Vulnerability in Android Leading to Local Escalation of Privilege
Weaknesses CWE-264
CWE-380

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:39:39.083Z

Reserved: 2026-03-02T19:11:09.008Z

Link: CVE-2026-28612

cve-icon Vulnrichment

Updated: 2026-09-10T14:39:35.527Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:53.330

Modified: 2026-09-15T14:17:47.540

Link: CVE-2026-28612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure