CVE-2025-26436
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-26436 is a Background Activity Launch (BAL) bypass vulnerability in Android's PendingIntentRecord.java, specifically in the clearAllowBgActivityStarts method, that allows a low-privileged application to launch activities from the background without user interaction. It affects Android versions 13.0, 14.0, and 15.0. The vulnerability was disclosed via the Android Security Bulletin dated May 1, 2025, and published to NVD on September 4, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), stemming from improper handling of background activity start allowances in PendingIntentRecord.java. The clearAllowBgActivityStarts method fails to correctly revoke permissions that allow an app to launch activities from the background, enabling a BAL bypass. Exploitation requires only local access with low privileges and no user interaction, making it straightforward for a malicious app already installed on the device to abuse this flaw. Patches are available via two commits to the Android platform frameworks/base repository (Android Security Bulletin, AOSP Commit 1, AOSP Commit 2).

Impact

Successful exploitation allows a low-privileged application to escalate privileges locally, with high impact to confidentiality, integrity, and availability of the affected Android device. An attacker can launch arbitrary activities from the background without user awareness or interaction, potentially enabling unauthorized access to sensitive UI components, data manipulation, or further privilege escalation. The scope is limited to the local device, but the ability to silently launch activities could facilitate phishing overlays, credential theft, or abuse of other application contexts (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.011%, reflecting limited near-term exploitation likelihood. Exploitation requires a malicious app to be installed on the target device with at least low-privilege access (Android Security Bulletin).

Exploitation steps

  1. Install malicious app: An attacker distributes a malicious Android application (e.g., via sideloading or a third-party app store) that requests minimal permissions to avoid suspicion.
  2. Trigger PendingIntent handling: The malicious app creates or manipulates a PendingIntent in a way that exploits the flawed clearAllowBgActivityStarts logic in PendingIntentRecord.java, preventing proper revocation of background activity start permissions.
  3. Launch background activity: The app leverages the retained BAL permission to launch an arbitrary activity from the background — without any user interaction or visible prompt.
  4. Achieve privilege escalation: The launched activity can belong to a higher-privileged context, enabling the attacker to access sensitive UI, overlay legitimate apps for phishing, or interact with system components beyond the app's normal authorization (Android Security Bulletin).

Indicators of compromise

  • Logs: Android system logs (logcat) showing unexpected activity launches from background processes, particularly involving PendingIntentRecord or ActivityTaskManager with unusual calling packages.
  • Process Behavior: Applications launching foreground activities without user interaction or visible triggers; unexpected UI overlays appearing on screen.
  • File System: Presence of sideloaded APKs (outside of Google Play) with minimal declared permissions but exhibiting background activity behavior.
  • Network: Unusual outbound connections from newly launched background activities to unknown remote endpoints, potentially indicating data exfiltration following privilege escalation.

Mitigation and workarounds

Google has released patches for Android 13.0, 14.0, and 15.0 via the Android Security Bulletin for May 2025 (patch level 2025-05-01). Device manufacturers and OEMs should apply these patches and push updates to end users promptly. Users should ensure their devices are updated to the latest available security patch level. As a precautionary measure, avoid installing applications from untrusted sources, and use Mobile Device Management (MDM) solutions to enforce security policies and restrict sideloading in enterprise environments (Android Security Bulletin).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in the May 2025 Android OS update, including CVE-2025-26436, could allow for privilege escalation (CIS Advisory). Samsung also addressed this CVE in its May 2025 security update for affected Galaxy devices. No significant independent researcher commentary or social media discussion has been observed for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68981HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-69153MEDIUM6.3
  • JavaScript logoJavaScript
  • unleash-server
NoYesAug 03, 2026
CVE-2026-68979MEDIUM5.9
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-64640MEDIUM5.3
  • Python logoPython
  • polaris
NoYesAug 06, 2026
CVE-2026-68980LOW2.3
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management