CVE-2026-28656: Security vulnerability
Published Sep 8, 2026
·Updated
In multiple places, there is a possible permission bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access and interaction does an attacker need?
Exploitation requires User execution privileges and user interaction. The issue is a tapjacking or overlay attack that can bypass permissions and lead to local privilege escalation.
2
Is this remotely exploitable?
The available information describes this as a local escalation-of-privilege issue and requires User execution privileges. It does not indicate remote exploitation.