CVE-2026-28593
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
⚡ Watch CVE-2026-28593
Get an email if CVE-2026-28593 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
- unknownAndroid Multiple Vulnerabilitieshkcert · 2026-09-09
- unknownCVE-2026-28593: In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to mi…nvd · 2026-09-08
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-28593)