CVE-2026-0013 is a confused-deputy vulnerability in the setupLayout implementation of Android DocumentsUI's PickActivity. A local attacker can cause arbitrary activities to be started in the security context of the DocumentsUI application, rather than their own application context, enabling local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is an Android Studio project that builds a local proof-of-concept app for CVE-2026-0013, described as an Android DocumentsUI confused-deputy issue involving PickActivity. The repo contains a standard Gradle Android app, CI workflow for cloud-building an APK, a GitHub Pages landing page, and supporting documentation. Core exploit logic resides in app/src/main/java/com/example/cve20260013exploit/ExploitActivity.java and IdTestActivity.java. ExploitActivity is the launcher activity. On startup it checks whether the device is in the claimed vulnerable range (API 34-36 / Android 14-16), then constructs crafted picker intents using ACTION_OPEN_DOCUMENT and ACTION_GET_CONTENT with CATEGORY_OPENABLE, MIME type */*, FLAG_GRANT_READ_URI_PERMISSION, and an injected Intent.EXTRA_INTENT pointing to the app's exported IdTestActivity. It first tries implicit resolution to DocumentsUI, then falls back to explicit component names for OEM and AOSP variants: com.android.documentsui.picker.PickActivity and com.android.documentsui.PickActivity. It logs the resolver chain and posts notifications describing which component was selected. IdTestActivity is the verification payload. If launched, it logs its actual PID/UID/process name, then executes local identity commands ('sh -c id', 'id', '/system/bin/id', '/system/xbin/id') and displays the output in a notification. This demonstrates whether the target activity was proxy-launched and under what identity it actually runs. The code and README explicitly acknowledge that the launched component still runs under the app's own UID unless privileged signing/sharedUserId/root is available, so the PoC is primarily a validation tool for intent handling and URI-grant behavior rather than a full privilege-escalation exploit. Repository structure: README.md and SECURITY_PROTOCOL.md provide context and disclaimers; AndroidManifest.xml declares exported ExploitActivity and IdTestActivity plus permissions such as INTERNET, POST_NOTIFICATIONS, and QUERY_ALL_PACKAGES; app/build.gradle defines an Android app targeting SDK 34; .github/workflows/build.yml builds a debug APK and publishes artifacts; index.html is a GitHub Pages front-end linking to builds and documentation. Overall, this is a local Android PoC/verification app for a DocumentsUI intent-confusion scenario, not a remote exploit or framework module.
This repository is a small Android Studio project implementing a local Android proof-of-concept exploit app for the claimed CVE-2026-0013. The core logic is concentrated in a single Java file, app/src/main/java/com/example/cve20260013exploit/ExploitActivity.java, with standard Android project scaffolding around it (Gradle build files, manifest, resources, and a GitHub Actions workflow to build an APK). Exploit capability: when launched, the app checks whether the device API level is 34-36 and then attempts to trigger a crafted intent chain. It builds an explicit intent for TermuxActivity (com.termux.app.TermuxActivity), attaches a selector intent disguised as a normal ACTION_PICK request for image/* content from MediaStore, then embeds that crafted intent inside another ACTION_PICK intent explicitly targeting DocumentsUI PickActivity (com.android.documentsui.PickActivity) via Intent.EXTRA_INTENT. The apparent goal is to exploit improper validation or selector handling in DocumentsUI so that the intermediary activity launches Termux. A fallback helper method exists to launch Termux normally for comparison, but it is not used in the main flow. Repository structure: the manifest declares the exploit activity as exported and launcher-enabled, requests INTERNET and QUERY_ALL_PACKAGES, and adds package visibility queries for com.termux and com.android.documentsui. The UI layout is minimal and mostly demonstrative. No command execution, shell payload, persistence, exfiltration, or network C2 behavior is present. Despite the INTERNET permission, the exploit does not contact remote hosts. The GitHub workflow simply builds and uploads debug/release APK artifacts. Assessment: this is a plausible local PoC-style exploit app rather than a detection script. It is not part of a known exploit framework. Its effect is limited to attempting to launch another installed app (Termux) through a crafted nested intent sequence; there is no post-exploitation payload beyond that behavior.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A confused-deputy vulnerability in DocumentsUI's PickActivity.java setupLayout logic that could let a local attacker start arbitrary activities as the DocumentsUI application, resulting in local privilege escalation without additional execution privileges or user interaction.
A local privilege escalation vulnerability in Android DocumentsUI (PickActivity.java) caused by a confused deputy condition that can allow starting arbitrary activities as the DocumentsUI app.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.