Cross-Profile Intent Filter Bypass in Android by Google
CVE-2025-22433

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
2 September 2025

What is CVE-2025-22433?

The vulnerability arises from a logic error in the canForward method of IntentForwarderActivity.java, enabling a bypass of the cross-profile intent filter. This is particularly relevant in Work Profile scenarios, permitting local escalation of privileges without requiring additional execution rights or user interaction. As a result, this flaw poses a significant risk by potentially allowing unauthorized access to sensitive data or functionalities within the affected Android environments.

Affected Version(s)

Android 15

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.