Android Package Installer Service Path Traversal Vulnerability Allowing Privilege Escalation
Vulnerability
A path traversal vulnerability has been identified in the PackageInstallerService component of Android. This issue allows a Device Policy Controller (DPC) to be updated into an invalid directory, potentially leading to unauthorized privilege escalation. The vulnerability exists in several versions of Android, including 14, 15, 16, and 16-qpr2. Exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Impact
Exploitation of this vulnerability could lead to unauthorized elevation of privileges, allowing a user to gain higher access rights than intended.
Remediation
Users can update their devices to the June 2026 security patch level to address this vulnerability. Instructions for checking and updating the Android version are available on the Google Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
