PT-2025-36010 · Google · Android

Published

2025-05-01

·

Updated

2025-09-05

·

CVE-2025-26425

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A permission squatting issue exists in multiple functions of RoleService.java due to a logic error in the code. This could lead to local escalation of privilege on Android versions where android.permission.MANAGE DEFAULT APPLICATIONS was not defined. Exploitation does not require user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

ASB-A-379362792
CVE-2025-26425

Affected Products

Android