Microphone Privacy Indicator Logic Flaw in Android Permission Manager
CVE-2025-26461

3.3LOW

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 September 2025

What is CVE-2025-26461?

In Android's Permission Manager, a logic error allows the microphone privacy indicator to incorrectly remain active even when users attempt to close the application. This flaw could potentially enable local escalation of privilege without requiring any additional execution permissions. The issue poses a privacy risk, as user interaction is not necessary for exploitation, thereby making it crucial for users to remain vigilant regarding app permissions and privacy indicators.

Affected Version(s)

Android 16

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26461 : Microphone Privacy Indicator Logic Flaw in Android Permission Manager