Denial of Service Vulnerability in DNG SDK by Android
CVE-2025-0081

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-0081?

The DNG SDK suffers from a vulnerability located in the dng_lossless_decoder::HuffDecode function. This issue arises due to uninitialized data handling, which could allow an attacker to induce a crash in the DNG processing functionality. Importantly, this vulnerability does not require user interaction nor additional execution privileges, enabling potential remote denial of service attacks. Proper validation and initialization of data can mitigate the risks associated with this issue.

Affected Version(s)

Android 15

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0081 : Denial of Service Vulnerability in DNG SDK by Android