PT-2025-24453 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-26420

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The vulnerability resides within the System component of the Android operating system, stemming from improper code generation management. Remote attackers can potentially execute arbitrary code by exploiting this issue. Additionally, multiple functions within GrantPermissionsActivity.java may mislead users into granting incorrect permissions due to permission overload, potentially leading to local privilege escalation without requiring additional execution privileges. Exploitation does not require user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Preservation of Permissions

Code Injection

Weakness Enumeration

Related Identifiers

ASB-A-313909156
BDU:2025-06592
CVE-2025-26420

Affected Products

Android