Android Device Policy Manager Service Race Condition Vulnerability Allowing Unauthorized App Installation in Work Profiles
Vulnerability
A race condition vulnerability has been identified in the DevicePolicyManagerService.java file, which could allow unauthorized applications to be installed in a newly created work profile. This issue arises from a timing flaw that could be exploited to bypass normal application installation restrictions. The vulnerability could lead to local privilege escalation, requiring no additional execution privileges or user interaction for exploitation.
Impact
Exploitation of this vulnerability could result in unauthorized applications being installed in a work profile, potentially leading to local privilege escalation.
Remediation
Users can update their devices to the April 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
