PT-2025-24445 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-26427

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A path traversal error exists in the Android Framework component, potentially allowing an attacker to gain local privilege escalation without requiring additional execution privileges. Exploitation requires user interaction. The vulnerability is due to a buffer copy operation without proper input size validation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

ASB-A-200034476
BDU:2025-06583
CVE-2025-26427

Affected Products

Android