A vulnerability was found in Google Android 17 and classified as critical. This vulnerability affects the function createSessionInternal of the file PackageInstallerService.java. Such manipulation leads to improper synchronization.

This vulnerability is listed as CVE-2026-0068. The attack must be carried out locally. There is no available exploit.