CVE-2026-0068
Awaiting Analysis Awaiting Analysis - Queue
PackageInstallerService DPC App Removal Without DO Consent

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Android (associated with Google Inc. or Open Handset Alliance)

Description
In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO consent due to desync from persistence. This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. User interaction is needed for exploitation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the createSessionInternal method of PackageInstallerService.java. It allows a possible way to remove a Device Policy Controller (DPC) app from a managed device without the Device Owner's (DO) consent due to a desynchronization issue with persistence.

Exploitation requires user interaction and could lead to a local escalation of privilege if a user installs a malicious app. Notably, no additional execution privileges are needed for the malicious app to exploit this vulnerability.

Impact Analysis

The vulnerability can impact you by allowing a local attacker to escalate their privileges on a managed device. Specifically, it could enable the removal of a Device Policy Controller app without proper authorization, potentially compromising device management and security controls.

Since the attacker can install a malicious app without needing additional execution privileges, this could lead to unauthorized actions on the device, undermining the security posture of the managed environment.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0068. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart