In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| Vendors & Products |
Google
Google android |
Wed, 09 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Background Activity Launch Bypass in Android LauncherAppsService Enables Local Escalation | |
| Weaknesses | CWE-250 CWE-285 CWE-640 |
Tue, 08 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-09-08T18:05:28.430Z
Updated: 2026-09-10T03:57:25.953Z
Reserved: 2026-03-02T19:11:24.241Z
Link: CVE-2026-28663
No data.
Status : Undergoing Analysis
Published: 2026-09-08T19:17:56.677
Modified: 2026-09-10T04:18:00.927
Link: CVE-2026-28663
No data.