CVE-2026-28614
massConfused-Deputy Permission Bypass in Android SlicePermissionActivity (LPE)
An app running locally on an Android device can exploit a confused-deputy flaw in the onCreate method of SlicePermissionActivity.java, tricking the system component into granting slice permissions without the intended authorization check. Exploitation requires no user interaction and no special privileges beyond having code running locally on the device (attacker requires only low privileges). A successful attack yields local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). The flaw resides in the Android open-source framework, so devices across the Android fleet are potentially affected, although the provided data does not specify vulnerable version ranges. There are currently no known exploits in the wild, no public proof of concept, and EPSS estimates only a 0.1% probability of exploitation within 30 days.
What to do: Apply the Android security update containing the fix as soon as Google or your device OEM publishes it, and confirm the updated patch level afterward. Until patched, reduce risk by installing apps only from trusted sources, since exploitation requires a malicious local app. Check the Android Security Bulletin and OEM advisories for the affected version ranges, which were not specified in the source data.
| Google Android (AOSP SlicePermissionActivity) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Vendors
- Products
- android
- Weakness
- CWE-441
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.