CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-28593

unknowncovered by 2 sourcesfirst seen 2026-09-08
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

⚡ Watch CVE-2026-28593

Get an email if CVE-2026-28593 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-28593

CVE.org record

Embed the live status

CVE-2026-28593 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-28593 status](https://www.csirts.com/badge/CVE-2026-28593)](https://www.csirts.com/cve/CVE-2026-28593)