Cross User Image Leak in Android Framework by Google
CVE-2024-49722

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
2 September 2025

What is CVE-2024-49722?

A vulnerability exists in the showAvatarPicker method of EditUserPhotoController.java within the Android Framework, allowing for a potential cross user image leak. This occurs because of a confused deputy pattern that could lead to unwanted local information disclosure without the need for additional execution privileges or user interaction for exploitation. As a result, sensitive user data may be exposed, highlighting the importance of immediate attention to affected systems.

Affected Version(s)

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-49722 : Cross User Image Leak in Android Framework by Google