Executive brief
A vulnerability in the Android DevicePolicyManagerService could allow an attacker to hide critical system software packages. This component is responsible for managing device policies and administrative functions on Android devices. If exploited, this could lead to a denial of service, potentially disabling essential security or management features without requiring any user interaction.
Technical details
A vulnerability exists in multiple functions of DevicePolicyManagerService.java within the Android Framework due to improper input validation. A local attacker can exploit this flaw to hide system-critical packages. This action can result in a local denial of service (DoS) condition. The exploit requires no additional execution privileges and no user interaction. The issue is addressed in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Initial publication of the Android Security Bulletin and NVD record.
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.