Memory Exhaustion Attack in Android Package Installer by Google
CVE-2026-28575
10CRITICAL
What is CVE-2026-28575?
A logic error in the Android Package Installer’s PackageInstaller.Session#transfer method allows for a memory exhaustion attack that could lead to local denial of service. Exploitation does not require any additional execution privileges or user interaction, making this vulnerability particularly critical for system stability.
Affected Version(s)
Android 17