---
id: CVE-2026-58834
title: >-
  In setPermissionGrantState of DevicePolicyManagerService.java, there is a
  possible persistent denial of service due to improper input validation
summary: >-
  In setPermissionGrantState of DevicePolicyManagerService.java, there is a
  possible persistent denial of service due to improper input validation. This
  could lead to local denial of service with no additional execution privileges
  needed. …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: Google
product: Android
affected:
  - Android 17
  - Android 16-qpr2
  - Android 16
  - Android 15
  - Android 14
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:23.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58834'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-10-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T19:10:37.537030Z'
ingestedAt: '2026-10-05T19:30:59.988Z'
---

## Overview

In setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
