MEDIUM
CVE-2026-28575
CVSS
5.5
Description
In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Summary dbcve.org
A logic error in PackageInstaller.Session#transfer within Android's PackageInstallerSession.java allows an attacker to trigger memory exhaustion, causing local denial of service. No additional privileges or user interaction are required for exploitation.
Mitigation
Apply Android security updates once available from Google; this is a framework-level bug requiring a patch to the AOSP code.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.13%
Probability of exploitation in next 30 days
2.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.