Android Device Policy Manager Service Race Condition Vulnerability Allowing Unauthorized App Installation in Work Profiles

Vulnerability

A race condition vulnerability has been identified in the DevicePolicyManagerService.java file, which could allow unauthorized applications to be installed in a newly created work profile. This issue arises from a timing flaw that could be exploited to bypass normal application installation restrictions. The vulnerability could lead to local privilege escalation, requiring no additional execution privileges or user interaction for exploitation.

Impact

Exploitation of this vulnerability could result in unauthorized applications being installed in a work profile, potentially leading to local privilege escalation.

Remediation

Users can update their devices to the April 2025 security patch level to address this vulnerability.

Added: Sep 2, 2025, 11:20 PM
Updated: Sep 2, 2025, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.5
remediation
0.0
relevance
0.5
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.