Local Privilege Escalation in Android Settings Notification Access
CVE-2025-22427
Currently unrated
What is CVE-2025-22427?
A logic error in the onCreate method of NotificationAccessConfirmationActivity.java in the Android Settings application could potentially allow users to grant notification access even when the device is locked. This vulnerability requires user interaction for exploitation and does not necessitate any additional execution privileges. As a result, it poses a local escalation of privilege risk, potentially compromising user data security.
Affected Version(s)
Android 15
Android 14
Android 13