PT-2025-24455 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-0077

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The Android Framework component contains a buffer copy flaw without input size validation. Exploitation of this flaw may allow an attacker to escalate privileges. A race condition exists in multiple functions within UserController.java, potentially allowing a local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

ASB-A-360838273
BDU:2025-06594
CVE-2025-0077

Affected Products

Android