In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Intent Validation Enables Local Privilege Escalation in Android | |
| Weaknesses | CWE-20 |
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-09-08T18:04:57.222Z
Updated: 2026-09-10T03:57:10.793Z
Reserved: 2026-03-02T19:11:09.009Z
Link: CVE-2026-28613
No data.
Status : Undergoing Analysis
Published: 2026-09-08T19:17:53.507
Modified: 2026-09-10T04:17:57.917
Link: CVE-2026-28613
No data.