CVE-2026-58834: Input Validation
Published Oct 5, 2026
·Updated
In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Oct 5, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
Can a local attacker exploit this without elevated execution privileges?
Yes. Exploitation requires only local access and no additional execution privileges.
2
Is user interaction required for exploitation?
No. The issue can be exploited without user interaction.