CVE-2026-0023 is a local privilege escalation vulnerability in Android's PackageInstallerService. The flaw is located in createSessionInternal of PackageInstallerService.java, where a missing permission check can allow an application to update its ownership improperly. By abusing this authorization weakness, a local app may be able to alter package ownership state in a way not intended by the platform's security model.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a local Android proof-of-concept lab for CVE-2026-0023, an Android PackageInstaller/Update Ownership trust bypass. It is not a remote exploit or malware kit; instead it demonstrates how a regular installer can influence an internal installation flag so Android suppresses the expected Update Ownership warning during updates on vulnerable builds. Repository structure: the project contains three separate Android Studio/Gradle apps. 'Safe Market' is a benign installer app that requests REQUEST_INSTALL_PACKAGES and ENFORCE_UPDATE_OWNERSHIP, lets the user pick an APK via OpenDocument, writes it into a PackageInstaller session as 'base.apk', and commits the install while handling the result through an internal action string. 'Sample app' is the target/demo application ('Ownership Inspector') that audits and displays installer-of-record, update owner, package source, signer, and related metadata so the user can observe the trust chain before and after updates. 'Unsafe Market' is the key exploit component: it mirrors the installer workflow but adds two modes (normal and CVE path), includes the ChickenHook RestrictionBypass dependency, and defines constants for the internal flag name 'INSTALL_FROM_MANAGED_USER_OR_PROFILE' and SessionParams field 'installFlags', indicating reflective manipulation of PackageInstaller session parameters to reproduce the vulnerable behavior. Main exploit capability: the unsafe installer can create a PackageInstaller session for a user-selected APK and, in the CVE mode, attempt to set the internal managed-profile install flag that should only be controlled by the system. On vulnerable Android versions, this causes Android to treat the install as if it came from a managed profile context and suppress the Update Ownership warning that would normally appear when a different installer updates an app with an established update owner. The result is a trust/UI bypass affecting update provenance, not arbitrary code execution. Operationally, the PoC is mature enough to be considered OPERATIONAL: it contains working Android apps, UI flows, install-session handling, and a concrete payload path, but the payload is fixed to demonstrating the warning bypass rather than delivering a customizable post-exploitation capability. No network C2, hardcoded IPs, exfiltration endpoints, persistence, or destructive behavior were identified. The attack vector is strictly local and requires user/device access plus a vulnerable Android build.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.