In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

cve CVE-2026-0014 1 source, 1 claim · Watch

NVD writes:
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. En isPackageNullOrSystem de AppOpsService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para su explotación. the claim

What it is to other things

affectsgoogle/android
NVD
made_bygoogle
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD6.2
receipt
Source
NVD
Its words
6.2
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-28 11:46 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16-qpr2"
              },
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*",
                "matchCriteriaId": "FD695F32-4A73-4846-B1A1-04FF266E9C15",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*",
                "matchCriteriaId": "3DE9F018-8704-476B-8D59-F63F8486E231",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*",
                "matchCriteriaId": "BE95A642-4330-4F65-B028-3BA597D30F32",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En isPackageNullOrSystem de AppOpsService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para su explotación."
      }
    ],
    "id": "CVE-2026-0014",
    "lastModified": "2026-09-27T06:16:54.347",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-0014",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-02T21:23:38.527888Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-03-02T19:16:29.913",
    "references": [
      {
        "source": "security@android.com",
        "url": "https://source.android.com/docs/security/bulletin/2026/2026-03-01"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://seclists.org/fulldisclosure/2026/Sep/67"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/09/25/4"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDAndroid
receipt
Source
NVD
Its words
Android
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCAndroid
2026-09-28 11:46 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16-qpr2"
              },
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*",
                "matchCriteriaId": "FD695F32-4A73-4846-B1A1-04FF266E9C15",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*",
                "matchCriteriaId": "3DE9F018-8704-476B-8D59-F63F8486E231",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*",
                "matchCriteriaId": "BE95A642-4330-4F65-B028-3BA597D30F32",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En isPackageNullOrSystem de AppOpsService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para su explotación."
      }
    ],
    "id": "CVE-2026-0014",
    "lastModified": "2026-09-27T06:16:54.347",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-0014",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-02T21:23:38.527888Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-03-02T19:16:29.913",
    "references": [
      {
        "source": "security@android.com",
        "url": "https://source.android.com/docs/security/bulletin/2026/2026-03-01"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://seclists.org/fulldisclosure/2026/Sep/67"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/09/25/4"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-28 11:46 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16-qpr2"
              },
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*",
                "matchCriteriaId": "FD695F32-4A73-4846-B1A1-04FF266E9C15",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*",
                "matchCriteriaId": "3DE9F018-8704-476B-8D59-F63F8486E231",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*",
                "matchCriteriaId": "BE95A642-4330-4F65-B028-3BA597D30F32",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En isPackageNullOrSystem de AppOpsService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para su explotación."
      }
    ],
    "id": "CVE-2026-0014",
    "lastModified": "2026-09-27T06:16:54.347",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-0014",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-02T21:23:38.527888Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-03-02T19:16:29.913",
    "references": [
      {
        "source": "security@android.com",
        "url": "https://source.android.com/docs/security/bulletin/2026/2026-03-01"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://seclists.org/fulldisclosure/2026/Sep/67"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/09/25/4"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGoogle
receipt
Source
NVD
Its words
Google
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
2026-09-29 17:49 UTCGoogle
2026-09-28 11:46 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16-qpr2"
              },
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*",
                "matchCriteriaId": "FD695F32-4A73-4846-B1A1-04FF266E9C15",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*",
                "matchCriteriaId": "3DE9F018-8704-476B-8D59-F63F8486E231",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*",
                "matchCriteriaId": "BE95A642-4330-4F65-B028-3BA597D30F32",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En isPackageNullOrSystem de AppOpsService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para su explotación."
      }
    ],
    "id": "CVE-2026-0014",
    "lastModified": "2026-09-27T06:16:54.347",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.5,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-0014",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-03-02T21:23:38.527888Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-03-02T19:16:29.913",
    "references": [
      {
        "source": "security@android.com",
        "url": "https://source.android.com/docs/security/bulletin/2026/2026-03-01"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://seclists.org/fulldisclosure/2026/Sep/67"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/09/25/4"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
zetlyn/cve-nvd · 2026-03-02
cvss 6.2 product Android status Modified vendor Google source