Cross-User Permission Bypass in Android Settings Application
CVE-2025-32333
7.8HIGH
What is CVE-2025-32333?
A logic error in the 'startSpaActivityForApp' method of the 'SpaActivity.kt' module in the Android Settings application allows for a cross-user permission bypass. This flaw could enable local escalation of privileges without requiring additional execution rights or user interaction, potentially compromising user security and privacy.
Affected Version(s)
Android 14