CVE-2026-28631: Security vulnerability
Published Sep 8, 2026
·Updated
In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
Does exploitation require the victim to approve or interact with a prompt?
No. The issue is described as exploitable without user interaction through a tapjacking or overlay attack that bypasses consent.
2
What level of access does an attacker need before exploiting this issue?
The vulnerability can lead to local escalation of privilege and does not require additional execution privileges. The provided information does not specify any further attacker prerequisites.