Description
In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Apply Patch
AI Analysis

Impact

In the onCreate method of ContactsPickerActivity.kt a potential UI deception flaw allows a tapjacking or overlay attack to mislead the user. This exposure could reveal local contact information without requiring any additional execution privileges. The vulnerability directly affects how the activity displays sensitive data and can be exploited by an adversary presenting a malicious overlay over the system UI.

Affected Systems

The affected product is the Android operating system, specifically the ContactsPickerActivity within the system UI. No specific version ranges are provided in the data, so the vulnerability potentially applies to all releases containing this activity until a fix is published.

Risk and Exploitability

The CVSS score of 3.3 and an EPSS score of less than 1% indicate a low severity and low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The description states that user interaction is not required for exploitation, indicating that the vulnerability can be triggered autonomously by an overlay attacker. With no patch or mitigation instructions supplied by the vendor, the risk remains that local contact data could be leaked to any overlay-capable application on the device.

Generated by OpenCVE AI on September 11, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Android OS to the latest security patch when it becomes available
  • Disable the \"Display over other apps\" permission for the Contacts app and any other sensitive system applications
  • Monitor for and block suspicious overlay activity using a trusted third‑party app if a vendor patch has not yet been released

Generated by OpenCVE AI on September 11, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Contact Picker UI Deception Leading to Local Contact Disclosure

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Tapjacking/Overlay in Android Contacts Picker
Weaknesses CWE-200

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Tapjacking/Overlay in Android Contacts Picker
Weaknesses CWE-200

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T16:26:51.550Z

Reserved: 2026-03-02T19:11:11.728Z

Link: CVE-2026-28630

cve-icon Vulnrichment

Updated: 2026-09-10T16:26:47.272Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:54.760

Modified: 2026-09-15T14:08:09.500

Link: CVE-2026-28630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')