Out of Bounds Write Vulnerability in Gralloc4 Affecting Android Devices
CVE-2025-32316

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 September 2025

What is CVE-2025-32316?

A vulnerability exists in Gralloc4, where a missing bounds check can lead to an out of bounds write. This flaw can potentially allow local information disclosure without requiring any additional execution privileges or user interaction. Attackers could exploit this vulnerability to access sensitive information stored in memory.

Affected Version(s)

Android 16

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32316 : Out of Bounds Write Vulnerability in Gralloc4 Affecting Android Devices