Impact
A background activity launch bypass exists in the buildIntentSenderForUser method of LauncherAppsService.java. The flaw allows a local application to start an activity without being in the foreground, leading to privilege escalation. No additional execution privileges or user interaction are required, so the flaw is straightforward to exploit by any app running on the device.
Affected Systems
The vulnerability resides in the Android operating system’s LauncherAppsService component. The specific Android OS versions impacted are not enumerated in the advisory, but the fix is included in the 2026‑09‑01 security bulletin for Google Android.
Risk and Exploitability
Because the exploit can be executed from the background with no user interaction, the risk to users is The CVSS score is 7.8 and the EPSS score indicates a low exploitation probability (< 1%). The vulnerability is not listed in the CISA KEV. Attack method, leading to privilege escalation without additional steps.
OpenCVE Enrichment