In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
History

Wed, 09 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsafe PendingIntent in Android Storage Manager
Weaknesses CWE-290

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published: 2026-09-08T18:05:40.385Z

Updated: 2026-09-10T03:57:30.995Z

Reserved: 2026-05-12T17:37:06.748Z

Link: CVE-2026-45528

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T19:17:58.007

Modified: 2026-09-10T04:18:01.500

Link: CVE-2026-45528

cve-icon Redhat

No data.