CVE-2026-28572

Google · Android

A tapjacking or overlay vulnerability in InstallLaunch.kt within Google Android allows for local escalation of privilege without user interaction.

Executive summary

A critical local privilege escalation vulnerability in Google Android 16-qpr2 could allow attackers to gain elevated system access through a misleading UI tapjacking attack.

Vulnerability

This vulnerability occurs in the onCreate function of InstallLaunch.kt, where a lack of UI protection permits a tapjacking or overlay attack. The flaw allows a local attacker to escalate privileges without requiring user interaction, as indicated by the CVSS vector (UI:N).

Business impact

The ability to perform local privilege escalation poses a significant risk to organizational data integrity and confidentiality. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to bypass standard Android security boundaries, potentially gaining full control over the device or sensitive application data.

Remediation

Immediate Action: Review the latest security bulletins from Google and apply the relevant Android security patches as soon as they become available for your specific device model.

Proactive Monitoring: Monitor device logs for unusual overlay activity or unexpected application launches that suggest unauthorized UI manipulation.

Compensating Controls: Enforce strict application installation policies and restrict the use of third party applications that request overlay permissions, which can reduce the attack surface for tapjacking attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise through local escalation, organizations should prioritize the deployment of the forthcoming security updates. Security teams must monitor the Android security bulletin for the specific release that addresses this flaw and ensure all managed devices are updated promptly to mitigate the risk of exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources