Executive brief
Android's DocumentsUI component contains a flaw in how it handles activity launching from the PickActivity class. An attacker can exploit this to start arbitrary activities with DocumentsUI's elevated permissions, leading to local privilege escalation on affected Android devices. This could allow malicious software to gain system-level access without requiring user interaction or special device configuration.
Technical details
This vulnerability is a confused deputy attack in Android's DocumentsUI framework, specifically in the setupLayout() method of PickActivity.java. The flaw allows an attacker to launch arbitrary activities by abusing DocumentsUI's privileged context. The attack requires no additional execution privileges and does not require user interaction. By leveraging this confused deputy vulnerability, local code can escalate privileges to gain system-level capabilities. The issue was patched in the Android security update with patch level 2026-03-01 or later, with patches committed to the AOSP repository.
Affected products
- Google Android prior to security patch level 2026-03-01
Timeline
- 2026-03-02: disclosed
- 2026-03-01: patched