CVE-2026-0084
massLocal Privilege Escalation via Background Activity Launch in Android HostEmulationManager
CVE-2026-0084 is a logic error in Android's HostEmulationManager.java, the component that manages host card emulation (part of the device's NFC service), that improperly allows an activity to be launched from the background. The flaw is triggered locally on a device and requires no user interaction and no additional execution privileges to exploit. An attacker with code execution in the context of a low-privileged local app could abuse the background activity launch to escalate privileges on the device. All Android devices shipping builds with the affected component are potentially exposed, though the source data does not specify affected version ranges. There is currently no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts short-term exploitation probability at only 0.1%.
What to do: Track the Android security bulletin for CVE-2026-0084 and apply the corresponding monthly security patch as it reaches devices through OEM updates, using Settings > System update on end-user devices and staged MDM rollouts in enterprise fleets. Because exploitation requires local access (e.g., a malicious app already on the device), screening side-loaded or third-party app risk is a reasonable interim mitigation. Given no public PoC and a 0.1% EPSS, urgency is moderate, but privileged-app developers should verify their apps cannot trigger unexpected background activity launches.
| Google (Android Open Source Project) Android (HostEmulationManager, host card emulation/NFC component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android
- Weakness
- CWE-693
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.