CVE-2026-28584: Denial of service in Google Android
CVE-2026-28584 is a logic error vulnerability in the createSessionInternal function of PackageInstallerService.java on Google Android. It allows a local attacker to cause a permanent denial of service (DoS) on the device without requiring additional privileges or user interaction. The vulnerability affects specific Android versions 16-qpr2 and 17. No CVSS score or official patch information is currently available.
AI Analysis
Technical Summary
This vulnerability arises from a logic error in the createSessionInternal method within PackageInstallerService.java on Google Android. Exploiting this flaw can cause a permanent denial of service condition on the affected device. The attack requires no additional execution privileges and does not require user interaction, making it a local DoS vulnerability. The affected versions explicitly identified are Android 16-qpr2 and 17. There is no CVSS score or vendor advisory indicating remediation status at this time.
Potential Impact
An attacker with local access can trigger a permanent denial of service on the affected Android device, potentially rendering it unusable until recovery actions are taken. No privilege escalation or remote exploitation is indicated. The impact is limited to denial of service without additional execution privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should limit local access to trusted parties and monitor for vendor updates.
CVE-2026-28584: Denial of service in Google Android
Description
CVE-2026-28584 is a logic error vulnerability in the createSessionInternal function of PackageInstallerService.java on Google Android. It allows a local attacker to cause a permanent denial of service (DoS) on the device without requiring additional privileges or user interaction. The vulnerability affects specific Android versions 16-qpr2 and 17. No CVSS score or official patch information is currently available.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from a logic error in the createSessionInternal method within PackageInstallerService.java on Google Android. Exploiting this flaw can cause a permanent denial of service condition on the affected device. The attack requires no additional execution privileges and does not require user interaction, making it a local DoS vulnerability. The affected versions explicitly identified are Android 16-qpr2 and 17. There is no CVSS score or vendor advisory indicating remediation status at this time.
Potential Impact
An attacker with local access can trigger a permanent denial of service on the affected Android device, potentially rendering it unusable until recovery actions are taken. No privilege escalation or remote exploitation is indicated. The impact is limited to denial of service without additional execution privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should limit local access to trusted parties and monitor for vendor updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- google_android
- Date Reserved
- 2026-03-02T19:11:00.351Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa0560aacd9273b490f4ec5
Added to database: 09/08/2026, 18:38:02 UTC
Last enriched: 09/08/2026, 22:52:43 UTC
Last updated: 09/08/2026, 22:52:43 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.