cve-2026-28663
HIGH CVSS 7.8 opencve
Description
In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Timeline
- Published
- 2026-09-08 19:17 UTC
- Last Modified
- 2026-09-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
opencve | ||
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
vulnrichment |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-28663",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "17"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "16-qpr2"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "generic",
"value": "16"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "matching",
"scores": [
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Android",
"source": "cna",
"vendor": "Google"
},
"product": "android",
"vendor": "google"
}
],
"created": "2026-09-09T15:00:07.767609+00:00",
"updated": "2026-09-11T02:15:10.962474+00:00",
"vendors": [
"google",
"google$PRODUCT$android"
]
},
"epss": {
"score": 0.00076
},
"mitre": {
"cpes": [],
"created": "2026-09-08T18:05:28.430000+00:00",
"description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/28xxx/CVE-2026-28663.json",
"references": [
"https://source.android.com/docs/security/bulletin/2026/2026-09-01"
],
"title": null,
"updated": "2026-09-10T14:36:00.757000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
"cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
"cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
],
"created": "2026-09-08T19:17:56.677000+00:00",
"description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-28663.json",
"references": [
"https://source.android.com/docs/security/bulletin/2026/2026-09-01"
],
"title": null,
"updated": "2026-09-23T19:43:18.260000+00:00",
"vendors": [
"google",
"google$PRODUCT$android"
],
"weaknesses": [
"CWE-863"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-08T18:30:00+00:00",
"data": [
{
"details": {
"new": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"old": null
},
"type": "description"
},
{
"details": {
"added": [
"https://source.android.com/docs/security/bulletin/2026/2026-09-01"
],
"removed": []
},
"type": "references"
}
],
"id": "afe619ed-1ff3-4e88-99ed-f0f3782deffa"
},
{
"created": "2026-09-09T15:15:00+00:00",
"data": [
{
"details": {
"new": "Background Activity Launch Bypass in Android LauncherAppsService Enables Local Escalation",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-250",
"CWE-285",
"CWE-640"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "579e4a10-8afe-4a9f-a7e2-0c640ad34480"
},
{
"created": "2026-09-10T09:45:00+00:00",
"data": [
{
"details": [
"google",
"google$PRODUCT$android"
],
"type": "first_time"
},
{
"details": {
"added": [
"google",
"google$PRODUCT$android"
],
"removed": []
},
"type": "vendors"
}
],
"id": "536ac915-bdfc-432a-9897-42eea3cc58a9"
},
{
"created": "2026-09-10T15:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-863"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "44056885-b3a0-4033-8dbd-b102be6c922d"
},
{
"created": "2026-09-10T18:15:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Background Activity Launch Bypass in Android LauncherAppsService Enables Local Escalation"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-250",
"CWE-285",
"CWE-640"
]
},
"type": "weaknesses"
}
],
"id": "5f1fd18f-4d2f-4f19-94e0-bc53445638c5"
},
{
"created": "2026-09-10T22:45:00+00:00",
"data": [
{
"details": {
"new": "Background Activity Launch Bypass Leading to Local Privilege Escalation",
"old": null
},
"type": "title"
}
],
"id": "b3dc2e74-f8f9-4679-a59c-420fc624a0b9"
},
{
"created": "2026-09-11T02:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Background Activity Launch Bypass Leading to Local Privilege Escalation"
},
"type": "title"
}
],
"id": "479d463b-c116-451c-b0ba-56a4e2b0fbdc"
},
{
"created": "2026-09-23T20:00:00+00:00",
"data": [
{
"details": {
"added": [
"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
"cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
"cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
}
],
"id": "3c289422-18f7-4d55-9d0e-1294688be9c2"
}
],
"cpes": {
"data": [
"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
"cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
"cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2026-09-08T18:05:28.430000+00:00",
"provider": "mitre"
},
"description": {
"data": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "vulnrichment"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00076
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://source.android.com/docs/security/bulletin/2026/2026-09-01"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-09-23T19:43:18.260000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"google",
"google$PRODUCT$android"
],
"providers": [
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-863"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-08T18:05:28.430000+00:00",
"description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-09-10T14:35:57.440000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/28xxx/CVE-2026-28663.json",
"weaknesses": [
"CWE-863"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)