CVE-2025-22429
- EPSS 0.05%
- Veröffentlicht 02.09.2025 22:11:17
- Zuletzt bearbeitet 04.09.2025 16:39:18
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVE-2025-22428
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:16
- Zuletzt bearbeitet 04.09.2025 16:39:12
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no...
CVE-2025-22427
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:15
- Zuletzt bearbeitet 04.09.2025 16:39:24
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pri...
CVE-2025-22423
- EPSS 0.2%
- Veröffentlicht 02.09.2025 22:11:14
- Zuletzt bearbeitet 04.09.2025 16:39:29
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation...
CVE-2025-22422
- EPSS 0.02%
- Veröffentlicht 02.09.2025 22:11:13
- Zuletzt bearbeitet 04.09.2025 16:39:34
In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in another due to a logic error in the code. This could lead to local escalation of privilege with no ad...
CVE-2025-22421
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:12
- Zuletzt bearbeitet 04.09.2025 16:39:43
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution pr...
CVE-2025-22419
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:11
- Zuletzt bearbeitet 04.09.2025 16:39:48
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interac...
CVE-2025-22418
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:10
- Zuletzt bearbeitet 04.09.2025 16:39:53
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-22417
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:09
- Zuletzt bearbeitet 04.09.2025 16:39:57
In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti...
CVE-2025-22416
- EPSS 0.01%
- Veröffentlicht 02.09.2025 22:11:08
- Zuletzt bearbeitet 04.09.2025 16:40:02
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...