CVE-2026-0023

HIGH

PackageInstallerService - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-0023. PoCs published by QM4RS.

AI-analyzed exploit summary The repository contains only a LICENSE file with no exploit code, technical details, or proof-of-concept implementation for CVE-2026-0023.

Description

In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (1)

github STUB
by QM4RS · poc
https://github.com/QM4RS/CVE-2026-0023-Update-Ownership-PoC

The repository contains only a LICENSE file with no exploit code, technical details, or proof-of-concept implementation for CVE-2026-0023.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Jun 10, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 0.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (3)
google/android 14.0
google/android 15.0
google/android 16.0 (5 CPE variants)
Published Mar 02, 2026
Tracked Since Mar 03, 2026