MEDIUM

CVE-2026-28575

Google Android 2026-06-17 CVSS v3.1
CVSS
5.5

Description

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Summary dbcve.org

A logic error in PackageInstaller.Session#transfer within Android's PackageInstallerSession.java allows an attacker to trigger memory exhaustion, causing local denial of service. No additional privileges or user interaction are required for exploitation.

Mitigation

Apply Android security updates once available from Google; this is a framework-level bug requiring a patch to the AOSP code.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.13%
Probability of exploitation in next 30 days
2.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE