Beveiligingsadvies

CVE-2026-28575

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-17 07:02:33
Laatst bijgewerkt 2026-06-17 14:01:52
Toegewezen door google_android
CVSS-score 10.0
Status PUBLISHED

Beschrijving

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.