Executive brief
A security flaw in the Android Package Manager could allow a malicious application or local user to bypass the device lock controller. This bypass could lead to an unauthorized increase in system privileges, potentially allowing access to restricted data or functions. Exploitation does not require any interaction from the device owner.
Technical details
A vulnerability in the Android Package Manager component (specifically within the Framework) arises from a missing permission check. This flaw allows a local attacker to bypass the device lock controller, leading to local escalation of privilege (EoP). The attack requires no additional execution privileges and no user interaction. The issue is addressed in Android 17 with security patch levels of 2026-07-01 or later. While some sources list a CVSS 4.0 score of 10.0, the local nature of the escalation typically aligns with the reported high severity (CVSS 7.8).
Affected products
- Google Android 17.0
Timeline
- 2026-06-16: advisory: Android 17 Security Release Notes published
- 2026-06-17: disclosed: NVD publication date