Local Privilege Escalation Vulnerability in Android DevicePolicyManagerService
CVE-2026-0078

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0078?

A vulnerability in the DevicePolicyManagerService of Android allows for a possible desynchronization in persistence due to improper input validation in the setGlobalProxy method. This flaw could potentially permit local escalation of privilege without requiring additional execution privileges and can be exploited without any user interaction. For more information, refer to the official Android security bulletin.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.