Android Bulletin · May 2026

Android Security Bulletin: May 2026 Intent Redirection Triage

Triage of Android's May 2026 security updates resolving framework intent redirection flaws and mutable PendingIntent hijacking vulnerabilities.

37
Security Issues
1
Framework Intent Hijack
7.8
CVSS Intent Flaw
High
App Developer Alert

Triagem Executiva e Veredito de Risco

Google fixed CVE-2024-23712 in the Android Framework, where system services accepted unvalidated nested Intents, allowing malicious applications to launch internal non-exported activities with system privileges.

Matriz Curada de Triagem de Vulnerabilidades

Identificador CVE Subsistema / Componente Impacto CVSS Exploração Ativa?
CVE-2024-23712Android Framework CoreIntent Redirection / EOP7.8 HighYES (PoC Available)
CVE-2024-23713Telecom SubsystemCall Interception Bypass6.8 MediumNo
CVE-2024-23714Package Manager ServiceArbitrary App Overwrite7.2 HighNo
ANÁLISE DE CÓDIGO EM DESTAQUE

Deep Dive: Android Framework Intent Redirection Teardown →

Review the Java diff in ActivityManagerService.java sanitizing target component identifiers before dispatching pending intents.

← Navegar no Diretório de Segurança Todas as Atualizações de Segurança →