Sceawere
Vulnerability Detail
CVE-2026-58834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DevicePolicyManagerService Persistent Denial Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 2h ago
- Vendor
- Product
- Android
- Attack Type
- Denial of service
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-05T19:17:24.537Z",
"pubdate": "2026-10-05T19:17:24.537Z",
"executiveSummary": "A persistent denial of service (DoS) vulnerability exists within the DevicePolicyManagerService.java component of the Android framework. The flaw stems from insufficient input validation during the processing of permission grant states via the setPermissionGrantState function.\nThis vulnerability allows a local attacker to induce a state of persistent service instability or system unavailability. Critically, the exploit requires no elevated execution privileges, nor does it necessitate user interaction, making it a highly accessible vector for local resource exhaustion.\nThe risk implication is significant as the DevicePolicyManagerService is a core system service responsible for managing device policies. Successful exploitation may lead to a persistent failure of the service, potentially affecting system-wide policy enforcement and overall device stability. Given the lack of requirements for authentication or user interaction, this vulnerability facilitates a straightforward path for local attackers to disrupt device functionality without traditional barriers.",
"technicalDetails": "The vulnerability is localized within the setPermissionGrantState function located in DevicePolicyManagerService.java. The root cause is categorized as an improper input validation flaw, where the system fails to correctly sanitize or validate parameters passed to the function before internal processing.\nIn the Android framework, setPermissionGrantState is typically invoked to manage runtime permissions for applications. By supplying malformed or specifically crafted inputs to this function, an attacker can trigger an unhandled exception or enter an invalid state within the service logic. Because DevicePolicyManagerService is a system-level process, an unhandled exception or critical state error within this context can lead to a crash or a permanent hang of the service process.\nThe attack flow proceeds as follows: First, an attacker identifies the target interface, which is exposed to local applications. Second, the attacker invokes the setPermissionGrantState method with malicious arguments designed to bypass existing validation checks. Third, the service attempts to process these parameters, leading to an inconsistent internal state or an uncaught exception. Finally, if the resulting state change is persisted by the system, the DoS condition persists even after a service restart or system reboot, effectively bricking the specific policy management capabilities of the device.\nThis flaw does not require the attacker to possess root privileges or any additional execution capabilities beyond standard local application permissions. There is no requirement for user interaction, as the attack can be executed programmatically by any application residing on the device. Because the exploitation targets the logic within the system server process, the payload behavior manifests as a breakdown in system service availability. The post-exploitation impact is characterized by the persistent degradation of system policy enforcement, potentially preventing the installation or removal of applications, or obstructing other critical device management operations until the underlying state is manually or programmatically remediated through privileged intervention."
}