CVE-2026-0099
Activity Launch from Background in Android HostEmulationManager
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the onNullBinding method of the HostEmulationManager.java file. Due to a logic error in the code, it is possible to launch an activity from the background.
Exploitation requires user interaction and does not need any additional execution privileges.
How can this vulnerability impact me? :
The vulnerability can lead to a local escalation of privilege, allowing an attacker to launch activities from the background.
This means an attacker with local access and requiring user interaction could potentially perform actions with higher privileges than intended.