ZeroHour

CVE-2026-28614

mass

Confused-Deputy Permission Bypass in Android SlicePermissionActivity (LPE)

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

An app running locally on an Android device can exploit a confused-deputy flaw in the onCreate method of SlicePermissionActivity.java, tricking the system component into granting slice permissions without the intended authorization check. Exploitation requires no user interaction and no special privileges beyond having code running locally on the device (attacker requires only low privileges). A successful attack yields local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). The flaw resides in the Android open-source framework, so devices across the Android fleet are potentially affected, although the provided data does not specify vulnerable version ranges. There are currently no known exploits in the wild, no public proof of concept, and EPSS estimates only a 0.1% probability of exploitation within 30 days.

What to do: Apply the Android security update containing the fix as soon as Google or your device OEM publishes it, and confirm the updated patch level afterward. Until patched, reduce risk by installing apps only from trusted sources, since exploitation requires a malicious local app. Check the Android Security Bulletin and OEM advisories for the affected version ranges, which were not specified in the source data.

Affected
Google Android (AOSP SlicePermissionActivity)
Estimated exposure
massbillions of Android devices plausibly affected (Android runs on roughly 3 billion+ active devices) — The flaw is in the AOSP framework code shipped across the Android fleet, whose global active install base exceeds 3 billion devices, though because the vulnerable version range is unspecified the truly affected subset is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-441
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.