
🟠 CVE-2026-0013 - High In setupLayout of http://PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no addit... https://www.thehackerwire.com/vulnerability/CVE-2026-0013/ https://t.co/uryCcqIgU6
Post summary
The post announces CVE-2026-0013, detailing a local privilege escalation via a confused deputy in PickActivity.java, but does not provide PoC, exploit code, or patch information.
