Cross-Profile Intent Filter Bypass in Android by Google
CVE-2025-22433
Currently unrated
What is CVE-2025-22433?
The vulnerability arises from a logic error in the canForward method of IntentForwarderActivity.java, enabling a bypass of the cross-profile intent filter. This is particularly relevant in Work Profile scenarios, permitting local escalation of privileges without requiring additional execution rights or user interaction. As a result, this flaw poses a significant risk by potentially allowing unauthorized access to sensitive data or functionalities within the affected Android environments.
Affected Version(s)
Android 15
Android 14
Android 13