CVE-2025-32345
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:59
- Zuletzt bearbeitet 08.09.2025 16:40:40
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of pri...
CVE-2025-32333
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:58
- Zuletzt bearbeitet 08.09.2025 14:06:10
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n...
CVE-2025-32332
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:57
- Zuletzt bearbeitet 08.09.2025 14:06:33
In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-32331
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:56
- Zuletzt bearbeitet 08.09.2025 14:07:51
In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n...
CVE-2025-32330
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:55
- Zuletzt bearbeitet 08.09.2025 14:08:06
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional exec...
CVE-2025-32327
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:54
- Zuletzt bearbeitet 08.09.2025 14:08:28
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2025-32326
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:53
- Zuletzt bearbeitet 08.09.2025 14:09:09
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...
CVE-2025-32325
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:52
- Zuletzt bearbeitet 08.09.2025 14:09:19
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-32324
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:51
- Zuletzt bearbeitet 08.09.2025 14:09:35
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVE-2025-32323
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:33:50
- Zuletzt bearbeitet 08.09.2025 14:09:46
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional execu...