CVE-2026-0014

Executive Summary

CVE-2026-0014: Android AppOpsService persistent denial of service via isPackageNullOrSystem input validation flaw. A local attacker can trigger a crash without privileges or user interaction, impacting device stability. No remote code execution or privilege escalation. Not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 6.2 (MEDIUM) - Published: 2026-03-02T19:16:29.913 - Last Modified: 2026-09-27T06:16:54.347

Original Description: In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

"Setting an example is not the main means of influencing another, it is the only means."

— Albert Einstein
Source: NVD