Description
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published: 2026-09-08
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Escalation of Privilege
Action: Apply Patch
AI Analysis

Impact

An insecure PendingIntent in Android's StorageManagerService allows a local attacker to trigger a LaunchAnyWhere chain that results in privilege escalation. Because the intent is not properly protected, an app with user interaction can cause the system to elevate its privileges without requiring additional execution rights. The flaw is rooted in improper authorization logic, making it a local privilege escalation risk.

Affected Systems

Google Android devices running versions affected by the 2026‑09‑01 security bulletin are vulnerable. Specific version ranges are not enumerated in the available data, so for patches that address this issue.

Risk and Exploitability

Attackers need only local presence and user interaction; no remote exploit is required. The vulnerability’s CVSS score is 7.3, the EPSS score is below 1%, and it is not listed in CISA KEV. The risk of local privilege escalation remains significant for any device that has not applied the latest security patch.

Generated by OpenCVE AI on September 11, 2026 at 00:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security patch that fixes the unsafe PendingIntent flaw.
  • Reboot the device to ensure the patch is fully applied.
  • Configure device administrator policies to restrict non‑trusted applications from using privileged storage operations.

Generated by OpenCVE AI on September 11, 2026 at 00:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unsafe PendingIntent in StorageManagerService Allows Local Privilege Escalation

Thu, 10 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsafe PendingIntent in Android StorageManagerService

Thu, 10 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsafe PendingIntent in Android StorageManagerService

Thu, 10 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsafe PendingIntent in Android Storage Manager
Weaknesses CWE-290

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-926
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsafe PendingIntent in Android Storage Manager
Weaknesses CWE-290

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T14:31:57.176Z

Reserved: 2026-05-12T17:37:06.748Z

Link: CVE-2026-45528

cve-icon Vulnrichment

Updated: 2026-09-10T14:05:11.716Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:17:58.007

Modified: 2026-09-24T15:51:45.100

Link: CVE-2026-45528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:15Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components