Local Privilege Escalation Vulnerability in System UI by Android
CVE-2025-32320

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 September 2025

What is CVE-2025-32320?

A vulnerability has been identified in the System UI component of Android that allows unauthorized access to view other users' images. This flaw arises from a confused deputy scenario, where improper validation of user permissions permits an attacker to escalate their privileges locally. Exploitation of this vulnerability does not require any additional execution privileges or user interaction, making it particularly concerning for user data privacy.

Affected Version(s)

Android 16

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32320 : Local Privilege Escalation Vulnerability in System UI by Android