ZeroHour

CVE-2026-28607

mass

Confused-deputy background-activity bypass leads to Android privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

Android contains a confused-deputy flaw (CWE-441) in multiple functions and multiple locations, where a trusted component launches background activity on behalf of another app, bypassing Android's background activity launch restrictions. A locally installed app with no additional execution privileges can trigger it, and no user interaction is required. Successful exploitation results in local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, AV:L/AC:L/PR:L/UI:N). All Android devices running affected builds are potentially exposed, although the bulletin data does not specify affected version ranges. No public proof of concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only about a 0.1% probability of exploitation in the next 30 days.

What to do: Apply the latest Android security patch from your device or OEM as soon as it addresses CVE-2026-28607, and check the Android Security Bulletin to confirm which builds are affected. Because exploitation requires local code execution with no special privileges, limit app installation to trusted sources on unpatched devices and monitor for updates, as there is no evidence of exploitation in the wild yet.

Affected
Google Android
Estimated exposure
massbillions of devices (global Android installed base), though only affected builds are vulnerable — Android runs on roughly 70% of the world's several billion active smartphones, so any local privilege escalation in the OS platform plausibly touches an installed base in the billions, even though exploitation requires local code execution…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-441
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.