PT-2025-35634 · Google · Android+1

Published

2025-04-01

·

Updated

2025-09-03

·

CVE-2025-22437

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description A logic error in the code within setMediaButtonReceiver of multiple files may allow launching arbitrary activities from the background. This could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ASB-A-317203980
CVE-2025-22437

Affected Products

Android
Platform/Frameworks/Base