CVE-2026-49887

In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 19:17

Updated : 2026-09-10 14:17


NVD link : CVE-2026-49887

Mitre link : CVE-2026-49887

CVE.ORG link : CVE-2026-49887


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel