CVE-2026-28631
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:54
- Zuletzt bearbeitet 15.09.2026 14:03:06
In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVE-2026-28633
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:54
- Zuletzt bearbeitet 15.09.2026 14:03:11
In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction i...
CVE-2026-28609
- EPSS 0.15%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:17:03
In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28611
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:17:24
In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...
CVE-2026-28612
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:17:47
In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...
CVE-2026-28613
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:22:34
In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is nee...
CVE-2026-28614
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:22:54
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2026-28616
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:23:18
In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...
CVE-2026-28617
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:23:43
In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28618
- EPSS 0.18%
- Veröffentlicht 08.09.2026 19:17:53
- Zuletzt bearbeitet 15.09.2026 14:24:07
In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.