Denial of Service Vulnerability in Android Device Policy Manager Service
CVE-2026-58834

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-58834?

A vulnerability in the DevicePolicyManagerService's setPermissionGrantState method allows for a persistent denial of service attack. This issue arises from improper input validation, which can be exploited locally to cause denial of service without requiring additional execution privileges or user interaction. The affected functionality can disrupt normal operations of the service.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.