Path Traversal Vulnerability in Android's Package Installer Service
CVE-2026-0055

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0055?

A vulnerability in Android's PackageInstallerService introduces a path traversal issue in the createSessionInternal function. This can potentially allow an attacker to update a Device Policy Controller (DPC) to an invalid directory. The flaw does not require user interaction for exploitation and could enable local escalation of privileges, posing significant risks to device security.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.