Android Notification Policy Desynchronization Vulnerability in Managed Services Component Allowing Local Privilege Escalation
Vulnerability
A vulnerability has been identified in the Android operating system within the ManagedServices.java file. The issue arises in the setPackageOrComponentEnabled function, where improper input validation creates a potential notification policy desynchronization. This vulnerability could lead to local privilege escalation, as it allows a user to gain elevated rights without requiring additional execution privileges or user interaction.
Impact
Exploitation of this vulnerability could result in unauthorized elevation of privileges, allowing a user to gain access to restricted functions or data.
Added: Mar 2, 2026, 7:24 PM
Updated: Mar 2, 2026, 10:12 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
3.3remediation
0.0relevance
3.4threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
