CVE-2026-28572: Security vulnerability
Published Sep 8, 2026
·Updated
In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The issue is exploitable through a tapjacking or overlay attack and does not require additional execution privileges. No user interaction is required.
2
What is the potential impact of successful exploitation?
Successful exploitation could result in local escalation of privilege through misleading UI behavior in InstallLaunch.kt.