PT-2025-36035 · Unknown · Shared.Java

Published

2025-09-01

·

Updated

2025-09-05

·

CVE-2025-32323

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shared.java (affected versions not specified)
Description The getCallingAppName function in Shared.java may allow an attacker to trick users into granting file access through deceptive text displayed in a permission popup. This is due to improper input validation. Successful exploitation could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ASB-A-397216537
BDU:2025-11555
CVE-2025-32323

Affected Products

Shared.Java