Impact
The vulnerability resides in PackageInstallerService.java’s createSessionInternal method, where a logic flaw can be leveraged to terminate the service without user interaction or elevated privileges. This flaw satisfies CWE‑693 (Improper Check for Operations Failure). An attacker who can trigger unusable, effectively denying all local users access to functions that depend on package installation or system updates.
Affected Systems
Google Android devices are affected. No specific Android versions are listed in the advisory, but PackageInstallerService method.
Risk and Exploitability
The exploit is local only; no remote access or privilege escalation is.5 indicates a medium severity. EPSS is < 1% and the issue is not listed in the CISA KEV catalog, suggesting a low likelihood of exploitation under current conditions. Nevertheless, an attacker with physical or local access could permanently compromise the device’s usability by repeatedly triggering the flaw, rendering the device inoperable.
OpenCVE Enrichment