CVE-2026-28607
massConfused-deputy background-activity bypass leads to Android privilege escalation
Android contains a confused-deputy flaw (CWE-441) in multiple functions and multiple locations, where a trusted component launches background activity on behalf of another app, bypassing Android's background activity launch restrictions. A locally installed app with no additional execution privileges can trigger it, and no user interaction is required. Successful exploitation results in local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, AV:L/AC:L/PR:L/UI:N). All Android devices running affected builds are potentially exposed, although the bulletin data does not specify affected version ranges. No public proof of concept is known, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only about a 0.1% probability of exploitation in the next 30 days.
What to do: Apply the latest Android security patch from your device or OEM as soon as it addresses CVE-2026-28607, and check the Android Security Bulletin to confirm which builds are affected. Because exploitation requires local code execution with no special privileges, limit app installation to trusted sources on unpatched devices and monitor for updates, as there is no evidence of exploitation in the wild yet.
| Google Android | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android
- Weakness
- CWE-441
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.