CVE-2025-26416
- EPSS 0.16%
- Veröffentlicht 02.09.2025 22:11:27
- Zuletzt bearbeitet 04.09.2025 16:37:27
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed f...
- EPSS 0%
- Veröffentlicht 02.09.2025 22:11:26
- Zuletzt bearbeitet 04.09.2025 16:37:40
In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. This could lead to local escalation of privilege with no additional exec...
CVE-2025-22439
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:25
- Zuletzt bearbeitet 04.09.2025 16:37:34
In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed...
CVE-2025-22438
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:24
- Zuletzt bearbeitet 04.09.2025 16:37:48
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-22437
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:23
- Zuletzt bearbeitet 04.09.2025 16:37:56
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVE-2025-22435
- EPSS 0.04%
- Veröffentlicht 02.09.2025 22:11:22
- Zuletzt bearbeitet 04.09.2025 16:38:05
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-22434
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:21
- Zuletzt bearbeitet 04.09.2025 16:38:14
In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee...
CVE-2025-22433
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:20
- Zuletzt bearbeitet 04.09.2025 16:38:21
In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scenarios due to a logic error in the code. This could lead to local escalation of privilege with no addit...
CVE-2025-22431
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:19
- Zuletzt bearbeitet 04.09.2025 16:39:07
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no addit...
CVE-2025-22430
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:18
- Zuletzt bearbeitet 04.09.2025 16:38:27
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is ...