Local Privilege Escalation Vulnerability in PackageInstallerService by Android
CVE-2026-0068

10CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
17 June 2026

What is CVE-2026-0068?

A vulnerability in the PackageInstallerService within Android allows for the potential removal of a Device Policy Controller (DPC) application from a managed device without the necessary consent from the DPC. This occurs due to a synchronization issue, potentially enabling a malicious user to exploit this flaw. If a user has the ability to install a malicious application, they can do so without gaining additional execution privileges. The attack requires user interaction to be successfully executed.

Affected Version(s)

Android 17

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.