Description
In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Escalation of Privilege
Action: Apply Patch
AI Analysis

Impact

In the Android IntentForwarderActivity, the buildMiniResolver function is vulnerable to a tapjacking or overlay attack that can bypass consent prompts. An attacker can coerce or misdirect a device user without requiring any user interaction, allowing the malicious activity to gain higher privileges on the device. The vulnerability facilitates privilege escalation locally and does not require the attacker to obtain additional execution rights beyond the normal Android permission framework.

Affected Systems

All Android devices running the affected build of the Android operating system, including versions published by Google prior to the availability of a publicly released patch. No specific version strings are listed in the advisory.

Risk and Exploitability

The Exploit Propensity Scoring System provides a score of 0.00121 for this issue, indicating a very low probability of exploitation. The CVSS score of 7.8 denotes high severity, and the described local privilege escalation potential and lack of required user interaction suggest a moderate to high risk despite the low exploitation likelihood. The attack vector is inferred to be local, relying on a UI overlay, and the attacker would need to co-locate on the device—no remote exploitation is described.

Generated by OpenCVE AI on September 10, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch when it becomes available
  • Disable or limit apps that can overlay the screen or request overlay permissions
  • Ensure apps are only granted permissions that are strictly required for their functionality and monitor for unexpected permission requests

Generated by OpenCVE AI on September 10, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*

Tue, 15 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Tapjacking Consent Bypass in Android IntentForwarderActivity Leading to Local Privilege Escalation

Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Tapjacking Consent Bypass Allowing Local Privilege Escalation in Android
Weaknesses CWE-264

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Tapjacking Consent Bypass Allowing Local Privilege Escalation in Android
Weaknesses CWE-264

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:36:29.865Z

Reserved: 2026-03-02T19:11:11.728Z

Link: CVE-2026-28631

cve-icon Vulnrichment

Updated: 2026-09-10T14:36:26.903Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:54.880

Modified: 2026-09-15T14:03:06.140

Link: CVE-2026-28631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')