CVE-2026-28602: Security vulnerability
Published Sep 8, 2026
·Updated
In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionWeakness
Frequently Asked Questions
1
Does exploitation require user interaction?
No. User interaction is not needed for exploitation.
2
What level of access does an attacker need?
This is a local escalation-of-privilege issue. The available information states that no additional execution privileges are needed for exploitation.
3
When was this issue published and last modified?
It was published on 2026-09-08 and last modified on 2026-09-08.