CVE-2026-0078
DevicePolicyManagerService Persistence Desync Vulnerability
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | devicepolicymanager | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the setGlobalProxy method of DevicePolicyManagerService.java. It involves a possible desynchronization in data persistence caused by improper input validation. This flaw can be exploited locally to escalate privileges without requiring any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The impact of this vulnerability is a local escalation of privilege. An attacker with local access could exploit this flaw to gain higher privileges on the device without needing extra execution rights or user involvement, potentially compromising system security.