ASB-A-488233632

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-488233632.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-488233632
Aliases
  • A-488233632
  • CVE-2026-28630
Published
2026-09-01T00:00:00Z
Modified
2026-09-08T15:39:03Z
Summary
[none]
Details

In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/packages/apps/ContactsPicker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17-next:0
Fixed
17-next:2026-09-01

Affected versions

Other
17-next

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/ContactsPicker/+/9c389023fc9bd5bb84ad44a027e2737d81340cd0"
    ],
    "severity": "High",
    "spl": "2026-09-01",
    "types": [
        "ID"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-488233632.json"

Android / platform/packages/apps/ContactsPicker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17:0
Fixed
17:2026-09-01

Affected versions

Other
17

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/ContactsPicker/+/aeb9081e881068a4cd584b81838efc36aa931c9b"
    ],
    "severity": "High",
    "spl": "2026-09-01",
    "types": [
        "ID"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-488233632.json"