« Back to list

CVE-2026-28599

Status: AnalyzedHigh (7.8)—

In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L + PR:L sin UI indica escalada local sin interacción (T1068). El bypass de Intent redirection en ActivityManagerService permite obtener privilegios elevados, impactando acceso a cuentas y permisos.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-28599",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-28599",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-10T03:57:04.781834Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@android.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Android",
          "versions": [
            {
              "status": "affected",
              "version": "17"
            },
            {
              "status": "affected",
              "version": "16-qpr2"
            },
            {
              "status": "affected",
              "version": "16"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-08T19:17:52.337",
  "references": [
    {
      "url": "https://source.android.com/docs/security/bulletin/2026/2026-09-01",
      "tags": [
        "Vendor Advisory",
        "Patch"
      ],
      "source": "security@android.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-693"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    }
  ],
  "lastModified": "2026-09-15T14:25:59.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED"
            },
            {
              "criteria": "cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9123E1DD-8607-427B-82B9-6E44B96C90F1"
            },
            {
              "criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@android.com"
}