CVE-2026-28572
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:51
- Zuletzt bearbeitet 15.09.2026 14:30:10
In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28582
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:51
- Zuletzt bearbeitet 15.09.2026 14:30:39
In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead to local information disclosure with no additional execution pri...
CVE-2026-28583
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:51
- Zuletzt bearbeitet 15.09.2026 14:31:00
In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2026-28584
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:51
- Zuletzt bearbeitet 15.09.2026 14:31:18
In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interact...
CVE-2026-28590
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:51
- Zuletzt bearbeitet 15.09.2026 14:31:39
In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVE-2026-0084
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:50
- Zuletzt bearbeitet 15.09.2026 14:29:54
In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...
CVE-2026-0054
- EPSS 0.11%
- Veröffentlicht 08.09.2026 19:17:49
- Zuletzt bearbeitet 15.09.2026 14:29:01
In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter...
CVE-2026-0065
- EPSS 0.12%
- Veröffentlicht 08.09.2026 19:17:49
- Zuletzt bearbeitet 15.09.2026 14:29:33
In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User ex...
CVE-2026-49883
- EPSS 0.19%
- Veröffentlicht 08.09.2026 19:10:22
- Zuletzt bearbeitet 14.09.2026 14:27:58
In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User ...
CVE-2025-36940
- EPSS 0.22%
- Veröffentlicht 24.08.2026 16:33:53
- Zuletzt bearbeitet 07.10.2026 09:10:00
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)