ASB-A-484844380

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-484844380.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-484844380
Aliases
  • A-484844380
  • CVE-2026-28572
Published
2026-09-01T00:00:00Z
Modified
2026-09-08T15:39:03Z
Summary
[none]
Details

In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17-next:0
Fixed
17-next:2026-09-01

Affected versions

Other
17-next

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/47ac32cb93e7739fa5dcb9fac8de912661ed675f"
    ],
    "severity": "High",
    "spl": "2026-09-01",
    "types": [
        "EoP"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-484844380.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-qpr2:0
Fixed
16-qpr2:2026-09-01

Affected versions

Other
16-qpr2

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/681e7dab998db0babde3275f4e7efa1150a95745"
    ],
    "severity": "High",
    "spl": "2026-09-01",
    "types": [
        "EoP"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-484844380.json"