CVE-2026-0013: [NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0013?
CVE-2026-0013 is classified as a high-severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2026-0013?
To mitigate CVE-2026-0013, it is recommended to update to the latest version of Android that addresses this vulnerability.
What type of vulnerability is CVE-2026-0013?
CVE-2026-0013 is a confused deputy vulnerability that allows unauthorized access to activities in the DocumentsUI app.
Who is affected by CVE-2026-0013?
CVE-2026-0013 affects devices running Android versions 14.0, 15.0, and 16.0.
Is user interaction required for exploiting CVE-2026-0013?
No, user interaction is not needed to exploit CVE-2026-0013.