CVE-2026-28593
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:25:06
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...
CVE-2026-28594
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:25:22
In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28596
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:25:40
In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not nee...
CVE-2026-28599
- EPSS 0.13%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:25:59
In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVE-2026-28600
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:26:16
In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVE-2026-28602
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:26:47
In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVE-2026-28603
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:27:17
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVE-2026-28604
- EPSS 0.16%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:27:45
In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28606
- EPSS 0.16%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:28:03
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User in...
CVE-2026-28607
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:52
- Zuletzt bearbeitet 15.09.2026 14:28:24
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...