CVE-2026-45528: Security vulnerability
Published Sep 8, 2026
·Updated
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is realistically exposed to exploitation?
Exploitation requires a local attacker. The issue is described as a local escalation of privilege, so it does not indicate remote exploitation.
2
Does an attacker need additional execution privileges or user involvement?
No additional execution privileges are needed, but user interaction is required for exploitation.