CVE-2026-28626: Security vulnerability
Published Sep 8, 2026
·Updated
In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
Exploitation is local and does not require additional execution privileges. User interaction is required.
2
What is the potential impact if exploitation succeeds?
Successful exploitation could allow an attacker to launch an arbitrary activity and escalate privileges locally.