PT-2025-24451 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-26428

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the LockTaskController.java component within the Android operating system. A logic error in the startLockTaskMode function may allow a bypass of the lock screen, potentially leading to physical escalation of privilege without requiring additional execution privileges. User interaction is required for exploitation. The vulnerability is related to a buffer copy operation without proper input size validation. Exploitation could allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Buffer Overflow

Weakness Enumeration

Related Identifiers

ASB-A-378514614
BDU:2025-06590
CVE-2025-26428

Affected Products

Android