PT-2025-25440 · Google · Android

Published

2025-06-01

·

Updated

2025-09-04

·

CVE-2025-26443

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the parseHtml function within HtmlToSpannedParser.java that may allow the installation of applications without enabling installation from unknown sources. This is due to a logic error in the code. Exploitation of this issue could lead to local privilege escalation, requiring no additional execution privileges. User interaction is required for successful exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

RCE

Weakness Enumeration

Related Identifiers

ASB-A-368319929
BDU:2025-06688
CVE-2025-26443

Affected Products

Android