PT-2025-24452 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-26423

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue resides within the System component of the Android operating system and is related to improper code generation management. Remote attackers may be able to execute arbitrary code by exploiting this issue. Additionally, a permanent denial-of-service (DoS) condition can be triggered due to a missing bounds check within the validateIpConfiguration function of the WifiConfigurationUtil.java file. This could lead to local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Code Injection

Weakness Enumeration

Related Identifiers

ASB-A-349550024
BDU:2025-06591
CVE-2025-26423

Affected Products

Android