CVE-2026-28599
Google · Android
A logic error in ActivityManagerService.java allows for an Intent Redirection Bypass in Google Android, resulting in local escalation of privilege without user interaction.
Executive summary
A high-severity local privilege escalation vulnerability in Google Android could allow an attacker with local access to compromise the integrity and confidentiality of the system.
Vulnerability
The vulnerability exists within the addCreatorToken function of ActivityManagerService.java due to a logic error that permits Intent Redirection. This flaw allows a local attacker with low privileges to escalate their permissions on the device without requiring user interaction.
Business impact
Successful exploitation of this vulnerability results in a total loss of confidentiality, integrity, and availability for the affected device. With a CVSS score of 7.8, the potential for unauthorized privilege escalation poses a significant risk to organizational data security, particularly for mobile fleets or devices handling sensitive internal information.
Remediation
Immediate Action: Users should apply the latest security updates provided by Google or their respective device manufacturer as soon as they become available.
Proactive Monitoring: Security teams should monitor device logs for unexpected process execution or suspicious activity originating from low-privileged applications.
Compensating Controls: Ensure that Mobile Device Management (MDM) policies restrict the installation of untrusted applications, as the attack vector requires a local presence on the device.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a clear risk of local privilege escalation that could be leveraged to bypass Android security boundaries. Organizations should prioritize the deployment of the September 2026 Android security patches to all managed devices to effectively mitigate this risk.
More Google CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written