Logic Error in Android Framework Grants Unintended Permissions to Secondary Users
CVE-2025-22428
Currently unrated
What is CVE-2025-22428?
A logic error in the Android Framework's hasInteractAcrossUsersFullPermission method can enable a primary user to grant permissions to an app for a secondary user. This flaw results in a local escalation of privilege, allowing unauthorized access without requiring additional execution privileges or user interaction. This vulnerability highlights the importance of stringent control over user permissions within the Android operating system, as it poses risks to the integrity and confidentiality of user data.
Affected Version(s)
Android 15
Android 14
Android 13