← לוח פגיעויות

CVE-2026-0055

בינונית 6.2

תיאור (מקור, אנגלית)

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

מדדים

CVSS 3.1
6.2 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-7/8/2026
CWE
CWE-22, CWE-269

מוצרים מושפעים

google: android

קישורים