Description
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Denial of service
Product status
16
15
14
13
References
android.googlesource.com/...38a09734a2d23656e5569643ad37fffe
source.android.com/security/bulletin/2025-09-01