CVE-2026-28664
- EPSS 0.08%
- Veröffentlicht 08.09.2026 19:17:56
- Zuletzt bearbeitet 23.09.2026 19:41:55
In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita...
CVE-2026-28666
- EPSS 0.18%
- Veröffentlicht 08.09.2026 19:17:56
- Zuletzt bearbeitet 23.09.2026 19:38:20
In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. Use...
CVE-2026-28668
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:56
- Zuletzt bearbeitet 23.09.2026 19:36:25
In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVE-2026-28634
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:03:40
In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U...
CVE-2026-28636
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:06:09
In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVE-2026-28638
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:06:20
In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...
CVE-2026-28639
- EPSS 0.14%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:08:18
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2026-28642
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:08:37
In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...
CVE-2026-28644
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:13:17
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ...
CVE-2026-28650
- EPSS 0.13%
- Veröffentlicht 08.09.2026 19:17:55
- Zuletzt bearbeitet 15.09.2026 14:13:58
In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...