Samsung PackageManagerService Data Authenticity Verification Vulnerability Allowing Modification of Application Installation Restrictions

Vulnerability

A vulnerability exists in the PackageManagerService on Samsung devices running Android 14, 15, and 16, prior to the March 2026 Security Maintenance Release. This vulnerability stems from insufficient verification of data authenticity, which enables local attackers to alter the installation restrictions of specific applications.

Impact

Exploitation of this vulnerability allows local attackers to modify the installation restrictions of certain applications, potentially leading to unauthorized application installations or changes in application behavior.

Remediation

Users can apply the March 2026 Security Maintenance Release to address this vulnerability.

Added: Apr 29, 2026, 5:18 AM
Updated: Apr 29, 2026, 5:18 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
7.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.