PT-2025-20040 · Google · Android

Wrlu

·

Published

2025-05-07

·

Updated

2025-05-07

·

CVE-2025-20955

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to SMR May-2025 Release 1
Description The issue concerns the improper export of Android application components in NotificationHistoryImageProvider, allowing local attackers to access notification images. This could potentially lead to unauthorized access to sensitive information.
Recommendations For versions prior to SMR May-2025 Release 1, update to the SMR May-2025 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the NotificationHistoryImageProvider component until a patch is available.

Fix

Related Identifiers

CVE-2025-20955

Affected Products

Android