CVE-2026-0065

Summary

In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

Affected Software

VendorProductVersion RangeStatus
GoogleAndroid16-qpr2affected
GoogleAndroid16affected
GoogleAndroid15affected
GoogleAndroid14affected

Weaknesses

  • Elevation of privilege

References