CVE-2026-28584

Summary

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

VendorProductVersion RangeStatus
GoogleAndroid17affected
GoogleAndroid16-qpr2affected

Weaknesses

  • Denial of service

References