CVE-2026-28663: High severity android vulnerability
Published Sep 8, 2026
·Updated
In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
4 affected components
android
Google Android=16.0
Google Android=16.0-qpr2
Google Android=17.0
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as a local escalation of privilege and requires no additional execution privileges. User interaction is not required.
2
What is the security impact of successful exploitation?
An attacker may be able to launch an activity from the background through a background activity launch bypass.