{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ogoogleandroid16.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*","cpe:2.3:o:google:android:16.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-0023"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Android (14.0, 15.0, 16.0)"],"_cs_severities":["high"],"_cs_tags":["android","vulnerability","security-bypass","mobile"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eCVE-2026-0023 is a security vulnerability in the Android PackageInstallerService, specifically within the \u003ccode\u003ecreateSessionInternal\u003c/code\u003e method. The vulnerability arises from the improper handling of the internal installation flag \u003ccode\u003eINSTALL_FROM_MANAGED_USER_OR_PROFILE\u003c/code\u003e. In vulnerable Android 14.0, 15.0, and 16.0 builds, this flag is not explicitly cleared during the session creation process.\u003c/p\u003e\n\u003cp\u003eAndroid utilizes an \u0026quot;update ownership\u0026quot; mechanism to notify users when an application is being updated by a source other than the original installer. By failing to clear the flag, a malicious application acting as an installer can manipulate the OS into bypassing this critical security warning. Instead of the expected alert identifying the update source, the user is presented with a generic, less restrictive update confirmation dialog. This behavior allows attackers to potentially replace legitimate applications with malicious versions while avoiding user scrutiny. The issue was addressed in the March 2026 Android security patch level.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker deploys a malicious application masquerading as a legitimate installer or package management utility.\u003c/li\u003e\n\u003cli\u003eThe malicious application initiates a package installation session via \u003ccode\u003ePackageInstallerService#createSessionInternal\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts the installation session parameters to exploit the failure to clear the \u003ccode\u003eINSTALL_FROM_MANAGED_USER_OR_PROFILE\u003c/code\u003e flag.\u003c/li\u003e\n\u003cli\u003eThe Android OS incorrectly evaluates the session, assuming it originates from a managed environment due to the uncleared flag.\u003c/li\u003e\n\u003cli\u003eThe OS bypasses the check that would normally trigger the \u0026quot;update ownership\u0026quot; warning dialog.\u003c/li\u003e\n\u003cli\u003eThe system displays a generic, non-specific update confirmation dialog to the user.\u003c/li\u003e\n\u003cli\u003eThe user, unaware that the update source has been switched, authorizes the installation of the malicious package update.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-0023 allows attackers to deceive users regarding the source of application updates. This undermines the Android update ownership trust chain, increasing the risk of unauthorized application replacement or the installation of malicious software under the guise of legitimate updates. The vulnerability affects a broad range of Android versions (14.0 through 16.0), potentially exposing a significant portion of the global Android user base to targeted application hijacking.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all devices running Android 14.0, 15.0, and 16.0 within the environment.\u003c/li\u003e\n\u003cli\u003eEnsure all managed mobile devices have received the Android security patch level of 2026-03-05 or later to resolve CVE-2026-0023.\u003c/li\u003e\n\u003cli\u003eImplement mobile device management (MDM) policies to restrict the installation of applications from unknown or untrusted sources.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual installation activities on managed Android devices that correlate with unauthorized or suspicious package installers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T06:53:52Z","date_published":"2026-10-10T06:53:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-android-update-ownership-bypass/","summary":"CVE-2026-0023 allows a malicious installer to suppress security warnings by manipulating internal installation flags, potentially facilitating the installation of malicious updates for legitimate applications.","title":"Android PackageInstallerService Update Ownership Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-android-update-ownership-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:google:android:16.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}