PT-2026-45583 · Google · Android

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-0070

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-0070

Affected Products

Android