CVE-2025-32330
- EPSS 0.02%
- Published 04.09.2025 18:33:55
- Last modified 08.09.2025 14:08:06
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional exec...
CVE-2025-32327
- EPSS 0.01%
- Published 04.09.2025 18:33:54
- Last modified 08.09.2025 14:08:28
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2025-32326
- EPSS 0.01%
- Published 04.09.2025 18:33:53
- Last modified 08.09.2025 14:09:09
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVE-2025-32325
- EPSS 0.01%
- Published 04.09.2025 18:33:52
- Last modified 08.09.2025 14:09:19
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-32324
- EPSS 0.01%
- Published 04.09.2025 18:33:51
- Last modified 08.09.2025 14:09:35
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVE-2025-32323
- EPSS 0.01%
- Published 04.09.2025 18:33:50
- Last modified 08.09.2025 14:09:46
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional execu...
CVE-2025-32321
- EPSS 0.01%
- Published 04.09.2025 18:33:49
- Last modified 08.09.2025 14:09:52
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is...
CVE-2025-26464
- EPSS 0.01%
- Published 04.09.2025 18:33:48
- Last modified 08.09.2025 14:10:13
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2025-26454
- EPSS 0.01%
- Published 04.09.2025 18:33:47
- Last modified 08.09.2025 14:10:25
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User...
CVE-2025-0089
- EPSS 0.02%
- Published 04.09.2025 18:33:46
- Last modified 08.09.2025 16:40:54
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...