Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samsung
Samsung mobile Devices |
|
| Vendors & Products |
Samsung
Samsung mobile Devices |
Wed, 29 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Modification of Application Installation Restrictions via PackageManagerService | |
| Weaknesses | CWE-285 |
Wed, 29 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SamsungMobile
Published:
Updated: 2026-04-29T04:46:46.051Z
Reserved: 2025-12-11T01:33:35.804Z
Link: CVE-2026-21023
No data.
Status : Received
Published: 2026-04-29T05:16:04.070
Modified: 2026-04-29T05:16:04.070
Link: CVE-2026-21023
No data.
OpenCVE Enrichment
Updated: 2026-04-29T07:00:04Z
Weaknesses