PT-2025-36021 · Google · Android

Published

2025-06-01

·

Updated

2025-09-04

·

CVE-2025-26450

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in IInputMethodSessionWrapper.java within the Android operating system. An untrusted application may inject key and motion events into the default Input Method Editor (IME) due to a missing permission check within the onInputEvent function. Successful exploitation could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-331730488
CVE-2025-26450

Affected Products

Android