Description
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch ASAP
AI Analysis

Impact

A permission bypass exists in the ActivityTaskManagerService.startNextMatchingActivity method, allowing a local attacker to elevate privileges without executing additional code or prompting the user. The flaw is a classic confused‑deputy scenario, classified as CWE‑441, in which privileged operations are performed on behalf of lower‑privileged callers.

Affected Systems

Android devices running the Android operating system, including any build that contains the vulnerable ActivityTaskManagerService component, are affected until the vendor releases a patch. Version specifics are not disclosed in the advisory.

Risk and Exploitability

The vulnerability is local and does not require user interaction. An attacker who can invoke the vulnerable method—such as a malicious app—can raise its privileges to that of the system. The CVSS score of 7.8 indicates high impact, while the EPSS score of less than 1% suggests a low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog, but the impact remains significant for any device that has not applied the official fix.

Generated by OpenCVE AI on September 10, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that addresses the ActivityTaskManagerService permission bypass.
  • Revise or revoke the permission that allows calls to startNextMatchingActivity so that only trusted system components retain access.
  • Deploy a mobile device management solution to enforce least privilege for installed apps and monitor for excessive permission use.

Generated by OpenCVE AI on September 10, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Fri, 11 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Permission Bypass in Android ActivityTaskManagerService Allows Local Privilege Escalation

Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Android ActivityTaskManagerService Permission Bypass Enables Local Privilege Escalation
Weaknesses CWE-273

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Android ActivityTaskManagerService Permission Bypass Enables Local Privilege Escalation
Weaknesses CWE-273

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:29:26.422Z

Reserved: 2026-03-02T19:11:16.421Z

Link: CVE-2026-28644

cve-icon Vulnrichment

Updated: 2026-09-10T14:29:23.246Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:55.543

Modified: 2026-09-15T14:13:17.673

Link: CVE-2026-28644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')