Android Multiple Vulnerabilities
Details
Original advisory: https://www.hkcert.org/security-bulletin/android-multiple-vulnerabilities_20260909
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-485640.07% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-485650.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-485660.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-00080.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-00100.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-00540.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-00650.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-00840.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-272800.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-285720.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Android Patchday September 2026: Mehrere Schwachstellencert-bund
- unknownCVE-2026-28666: In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial…nvd
- highCVE-2026-28664: In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic err…nvd
- unknownCVE-2026-28663: In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an …nvd
- unknownCVE-2026-28662: In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write du…nvd
- unknownCVE-2026-28660: In getAllSessions of multiple files, there is a possible confused deputy due to a logic error …nvd
- unknownCVE-2026-28658: In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in …nvd
- unknownCVE-2026-28657: In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI…nvd
- unknownCVE-2026-28656: In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a t…nvd
- unknownCVE-2026-28655: In multiple functions of RemoteViews.java, there is a possible background activity launch bypa…nvd
- unknownCVE-2026-28653: In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer …nvd
- unknownCVE-2026-28652: In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing pe…nvd
More from HKCERT Security Bulletins
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownMongoDB Multiple Vulnerabilities2026-09-10
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-10
- unknownCitrix Products Multiple Vulnerabilities2026-09-10
- unknownMozilla Firefox Denial of Service Vulnerability2026-09-09