Impact
In the PackageInstallerService.java, the createSessionInternal method contains a path traversal flaw that allows a malicious caller to direct a Device Policy Controller to write into an unintended filesystem location. This permits local privilege escalation, granting the attacker system‑level permissions without executing additional code. No user interaction is required, so the exploitation can occur solely from an internal app context.
Affected Systems
The vulnerability impacts Google Android devices that include the default PackageInstallerService, across all builds of Android that have not yet received the corresponding security patch. No specific Android version is indicated, so administrators should verify that the installed OS contains the vulnerable code.
Risk and Exploitability
The flaw permits an attacker who can run code locally to manipulate the installer’s path handling, resulting in privilege escalation. Because the exploit requires no user interaction, any local app with sufficient privileges can abuse it. The EPSS score is below 1%, indicating a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog, suggesting that exploitation has not been widely reported yet. With a CVSS score of 6.2 the vulnerability is considered moderate severity, though local privilege escalation still poses a significant risk to device integrity. Nonetheless, the local nature and moderate severity of the impact make it a notable risk to device integrity.
OpenCVE Enrichment