CVE-2026-28663: Security vulnerability
Published Sep 8, 2026
·Updated
In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as a local escalation of privilege and requires no additional execution privileges. User interaction is not required.
2
What is the security impact of successful exploitation?
An attacker may be able to launch an activity from the background through a background activity launch bypass.