CVE Vulnerabilities

CVE-2025-22415

Incorrect Privilege Assignment

Published: Sep 04, 2025 | Modified: Sep 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)

Potential Mitigations

References