Local Privilege Escalation Vulnerability in Android System Settings
CVE-2025-26419

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-26419?

A logic error in the initPhoneSwitch method of the SystemSettingsFragment.java code may allow a local attacker to bypass Factory Reset Protection (FRP). This vulnerability can lead to privilege escalation requiring user interaction for exploitation, enabling unauthorized access to functionalities that should be restricted.

Affected Version(s)

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.