CVE-2026-0013 Details
Description
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
A vulnerability has been identified in the PickActivity.java file of the Android DocumentsUI application. This issue arises from a confused deputy problem, which creates a potential avenue for starting any activity as a DocumentsUI app. Exploiting this vulnerability could lead to local privilege escalation, with no additional execution privileges required. Notably, user interaction is not necessary for exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 14.0 15.0 16.0 - |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | CVE Modified | CVE |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 22, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 3, 2026 | Initial Analysis | [email protected] |
| Mar 2, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | New CVE Received | [email protected] |