CVE-2026-21097: Google ActivityTaskManagerService (Android) vulnerability
Published Sep 9, 2026
·Updated
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Affected Software
1 affected component
Google ActivityTaskManagerService (Android)<SMR Sep-2026 Release 1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires a local attacker with privileged access. The available information does not indicate that unprivileged or remote attackers can exploit it.
2
What could a successful attacker do?
A successful attacker could launch an arbitrary activity through ActivityTaskManagerService.
3
Which releases are affected?
The issue affects ActivityTaskManagerService versions prior to SMR Sep-2026 Release 1. The provided information does not identify specific Android or device versions.