Impact
The vulnerability resides in multiple functions of Android's RemoteViews class, where a logic error allows applications to start activities in the background without proper authorization. This flaw permits a local attacker to elevate privileges on the device, gaining higher system capabilities without the need for additional execution privileges or user interaction. The weakness is a control‑flow bypass that violates intended access restrictions, enabling an app to execute privileged actions indirectly.
Affected Systems
Google Android operating systems are affected, specifically all device variants that include the vulnerable RemoteViews code. No specific version is listed in the September 2026 security bulletin, indicating that all Android releases present on or before that date may contain the flaw.
Risk and Exploitability
The CVE is designated as a local privilege escalation with no user interaction required. The EPSS score is < 1% and the vulnerability is not catalog. The CVSS score is 7.8, indicating a high severity. Because the flaw is present in system code, but the low EPSS score suggests that exploitation prevalence is execute the bypass without external triggers.
OpenCVE Enrichment