
Andriod LPE CVE: CVE-2026-0023 PT ID: PT-2026-4703 Vendor: Google Product: Android CVSS: 7.8 Credits: n/a Description: In createSessionInternal of http://PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-0023 • https://source.android.com/docs/security/bulletin/2026/2026-03-01 PoC/Exploit: https://github.com/QM4RS/CVE-2026-0023-Update-Ownership-PoC #dbugs_vuln
Post summary
The post announces CVE-2026-0023, a local privilege escalation in Android's PackageInstallerService, and publishes a PoC, but does not report active exploitation or a patch.



