CVE-2026-0013Disclosure(google / android)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
android

3 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-03: 1Technical Details · 2026-03-03: 103-03
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-0013 - High In setupLayout of http://PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no addit... https://www.thehackerwire.com/vulnerability/CVE-2026-0013/ https://t.co/uryCcqIgU6

    Post summary

    The post announces CVE-2026-0013, detailing a local privilege escalation via a confused deputy in PickActivity.java, but does not provide PoC, exploit code, or patch information.

    0000049
    121 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--

Explore more