cve-2026-28663

HIGH CVSS 7.8 opencve
Description

In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Timeline
Published
2026-09-08 19:17 UTC
Last Modified
2026-09-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H nvd
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H opencve
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H vulnrichment
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-28663",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "17"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "16-qpr2"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "generic",
              "value": "16"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "matching",
          "scores": [
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Android",
          "source": "cna",
          "vendor": "Google"
        },
        "product": "android",
        "vendor": "google"
      }
    ],
    "created": "2026-09-09T15:00:07.767609+00:00",
    "updated": "2026-09-11T02:15:10.962474+00:00",
    "vendors": [
      "google",
      "google$PRODUCT$android"
    ]
  },
  "epss": {
    "score": 0.00076
  },
  "mitre": {
    "cpes": [],
    "created": "2026-09-08T18:05:28.430000+00:00",
    "description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/28xxx/CVE-2026-28663.json",
    "references": [
      "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
    ],
    "title": null,
    "updated": "2026-09-10T14:36:00.757000+00:00",
    "vendors": [],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
      "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
    ],
    "created": "2026-09-08T19:17:56.677000+00:00",
    "description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-28663.json",
    "references": [
      "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
    ],
    "title": null,
    "updated": "2026-09-23T19:43:18.260000+00:00",
    "vendors": [
      "google",
      "google$PRODUCT$android"
    ],
    "weaknesses": [
      "CWE-863"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-08T18:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "added": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
              ],
              "removed": []
            },
            "type": "references"
          }
        ],
        "id": "afe619ed-1ff3-4e88-99ed-f0f3782deffa"
      },
      {
        "created": "2026-09-09T15:15:00+00:00",
        "data": [
          {
            "details": {
              "new": "Background Activity Launch Bypass in Android LauncherAppsService Enables Local Escalation",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-250",
                "CWE-285",
                "CWE-640"
              ],
              "removed": []
            },
            "type": "weaknesses"
          }
        ],
        "id": "579e4a10-8afe-4a9f-a7e2-0c640ad34480"
      },
      {
        "created": "2026-09-10T09:45:00+00:00",
        "data": [
          {
            "details": [
              "google",
              "google$PRODUCT$android"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "google",
                "google$PRODUCT$android"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "536ac915-bdfc-432a-9897-42eea3cc58a9"
      },
      {
        "created": "2026-09-10T15:30:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-863"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 7.8,
                  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                },
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "44056885-b3a0-4033-8dbd-b102be6c922d"
      },
      {
        "created": "2026-09-10T18:15:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Background Activity Launch Bypass in Android LauncherAppsService Enables Local Escalation"
            },
            "type": "title"
          },
          {
            "details": {
              "added": [],
              "removed": [
                "CWE-250",
                "CWE-285",
                "CWE-640"
              ]
            },
            "type": "weaknesses"
          }
        ],
        "id": "5f1fd18f-4d2f-4f19-94e0-bc53445638c5"
      },
      {
        "created": "2026-09-10T22:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "Background Activity Launch Bypass Leading to Local Privilege Escalation",
              "old": null
            },
            "type": "title"
          }
        ],
        "id": "b3dc2e74-f8f9-4679-a59c-420fc624a0b9"
      },
      {
        "created": "2026-09-11T02:30:00+00:00",
        "data": [
          {
            "details": {
              "new": null,
              "old": "Background Activity Launch Bypass Leading to Local Privilege Escalation"
            },
            "type": "title"
          }
        ],
        "id": "479d463b-c116-451c-b0ba-56a4e2b0fbdc"
      },
      {
        "created": "2026-09-23T20:00:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
                "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          }
        ],
        "id": "3c289422-18f7-4d55-9d0e-1294688be9c2"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
        "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2026-09-08T18:05:28.430000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 7.8,
          "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "vulnrichment"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.00076
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": null,
      "provider": null
    },
    "updated": {
      "data": "2026-09-23T19:43:18.260000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "google",
        "google$PRODUCT$android"
      ],
      "providers": [
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-863"
      ],
      "providers": [
        "nvd",
        "vulnrichment"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-08T18:05:28.430000+00:00",
    "description": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 7.8,
        "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-09-10T14:35:57.440000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/28xxx/CVE-2026-28663.json",
    "weaknesses": [
      "CWE-863"
    ]
  }
}
Enrichment data
View JSON API Download JSON