Metrics
Affected Vendors & Products
Tue, 02 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Desynchronization in Android DevicePolicyManagerService Enables Local Privilege Escalation |
Tue, 02 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Desynchronization in DevicePolicyManagerService Proxy Setting |
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 02 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Desynchronization in DevicePolicyManagerService Proxy Setting | |
| First Time appeared |
Google
Google android |
|
| Weaknesses | CWE-20 | |
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-06-01T21:14:54.115Z
Updated: 2026-06-02T14:27:14.299Z
Reserved: 2025-10-15T15:41:06.325Z
Link: CVE-2026-0078
Updated: 2026-06-02T12:55:19.707Z
Status : Undergoing Analysis
Published: 2026-06-01T22:16:21.940
Modified: 2026-06-02T16:16:31.400
Link: CVE-2026-0078
No data.