Impact
The vulnerability resides in the maybeRemoveInvalidInstallerPackageName function of InstallRepository.kt, where a permissions bypass allows an unprivileged application to replace or modify another installed package. This flaw exemplifies a lack of integrity checks (CWE-288). Because the check is omitted, an attacker can install a malicious or altered application under the identity of a trusted package without any additional privileges or user interaction, resulting in local privilege escalation.
Affected Systems
Google Android operating system, specifically the package installation subsystem implemented in the core framework. Devices running any Android version prior to the security bulletin published on 2026‑09 InstallRepository component used for all app installation and update operations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation vulnerability. The EPSS score is reported as < 1%, indicating a very low but non‑zero likelihood of exploitation as of the analysis date. The vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation to date. Attackers would invoke the normal permission checks, and could do so with only local or physical access. No user interaction is required, and the attacker need not obtain additional execution privileges to trigger the flaw.
OpenCVE Enrichment