ZeroHour

CVE-2026-28655

mass

Local Privilege Escalation via Background Activity Launch Bypass in Android

CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-28655 is a logic error in multiple functions of RemoteViews.java, a component of the Android framework, that allows a bypass of Android's background activity launch (BAL) restrictions (CWE-693, protection mechanism failure). It is triggered locally by an application with no special privileges, and no user interaction is required for exploitation. A successful attacker achieves local escalation of privilege, gaining the ability to launch activities in the background beyond the restrictions intended to limit unprivileged apps. All Android devices running framework code containing the flaw are potentially affected, though the source data does not specify affected version ranges or patch levels. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days (3rd percentile).

What to do: Apply the Android security update that addresses CVE-2026-28655 as delivered via Google's Android Security Bulletin and device OEM/manufacturer update channels, since the source data does not name specific affected versions or fixed patch levels. Fleet administrators should use MDM tooling to confirm which devices have received the relevant security patch level and prioritize OS updates. Given the very low EPSS score and absence of public exploitation, this is not urgent, but framework local privilege escalation flaws of this kind are frequently chained with other bugs, so timely patching is still recommended.

Affected
Google Android (framework component: RemoteViews.java)
Estimated exposure
mass≈3 billion+ active Android devices potentially affected pending patching (mass: Android's global install base) — Android powers roughly 70% of the multi-billion-device global smartphone market per public market-share data, and Android framework logic errors of this type generally affect the entire unpatched device fleet, so the upper bound of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors
google
Products
android
Weakness
CWE-693
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.