downloaded APK packages are not verified against APKINDEX checksum (package substitution possible)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE registry state
PUBLISHED
CVE state checked
F-APKO-CHECKSUM-001: Verification failures. Package checksums are not enforced on the affected path. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.