Description
In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The Android framework’s onActivityResult method in AppWidgetConfigActivityProxy.java contains a flaw that grants an application permission to access a URI it should not be able to access. The flaw also corresponds (CWE‑441), as the unauthorized URI permission is granted based on user‑supplied data. This is a classic confused‑deputy vulnerability that enables an app to elevate its privileges locally without needing elevated execution rights. The result is that an attacker with local device access can gain unauthorized access to resources protected behind URI permissions, potentially compromising confidential data or enabling further exploitation.

Affected Systems

Google Android devices are affected whenever the AppWidgetConfigActivityProxy component processes widget configuration callbacks. No specific Android release or API level is identified in the advisory, implying that the vulnerability could exist across multiple releases until a patch is applied. Users of any Android device running a version that has not yet incorporated the fix are at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of < 1% indicates a very low exploitation probability at present, but the local nature of the attack means that an attacker who already has physical or local access can exploit the flaw independently of remote vectors. The vulnerability is not listed in the CISA KEV catalog, yet its local privilege escalation potential warrants prompt attention. Exploitation requires no user interaction; an attacker simply needs to trigger the activity result flow used by applications that configure widgets.

Generated by OpenCVE AI on September 10, 2026 at 23:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that fixes AppWidgetConfigActivityProxy, as documented in the official Android security bulletin for 09‑01
  • Limit the use of widget configuration intents to trusted applications by validating the caller or disabling the configuration feature when it is unnecessary
  • Audit device logs for unexpected URI permission grants or unusually privileged intents and investigate any anomalies

Generated by OpenCVE AI on September 10, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Thu, 10 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized URI Permission Grant in Android Widget Configuration

Thu, 10 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized URI Permission Grant Enables Local Privilege Escalation in Android AppWidgetConfigActivityProxy
Weaknesses CWE-285
CWE-732

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-441
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthorized URI Permission Grant Enables Local Privilege Escalation in Android AppWidgetConfigActivityProxy
Weaknesses CWE-285
CWE-732

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:26:27.856Z

Reserved: 2026-03-02T19:11:19.581Z

Link: CVE-2026-28657

cve-icon Vulnrichment

Updated: 2026-09-10T14:26:23.813Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:56.207

Modified: 2026-09-15T14:15:24.490

Link: CVE-2026-28657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:15:08Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')