Local Privilege Escalation Vulnerability in PackageInstallerService by Android
CVE-2026-0068
10CRITICAL
What is CVE-2026-0068?
A vulnerability in the PackageInstallerService within Android allows for the potential removal of a Device Policy Controller (DPC) application from a managed device without the necessary consent from the DPC. This occurs due to a synchronization issue, potentially enabling a malicious user to exploit this flaw. If a user has the ability to install a malicious application, they can do so without gaining additional execution privileges. The attack requires user interaction to be successfully executed.
Affected Version(s)
Android 17