Executive brief
A security flaw in Android's package installation system could allow a malicious application to remove Device Policy Controller (DPC) apps without the required administrative consent. DPC apps are critical for managing corporate-owned or managed devices, and their unauthorized removal could bypass security policies and management controls. This could allow a user to gain unauthorized control over a managed device, potentially compromising corporate data or security configurations.
Technical details
A race condition (CWE-362) exists in the 'createSessionInternal' method of 'PackageInstallerService.java' due to a synchronization desync from persistence. This vulnerability allows a local attacker to remove a Device Policy Controller (DPC) application from a managed device without the consent of the Device Owner (DO). Exploitation requires the installation of a malicious app and user interaction, but requires no additional execution privileges. Successful exploitation leads to local escalation of privilege (EoP) by bypassing device management restrictions. The issue is addressed in Android 17 with security patch level 2026-07-01.
Affected products
- Google Android 17
Timeline
- 2026-06-16: advisory: Android 17 Security Release Notes published
- 2026-06-17: disclosed: CVE published to NVD