Privilege Escalation Vulnerability in Android Framework
CVE-2025-32349

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-32349?

A privilege escalation vulnerability exists within the Android Framework that can be exploited via a tapjacking or overlay attack. This flaw allows an attacker to elevate user privileges locally without requiring additional execution permissions or user interaction, creating potential security risks for affected devices.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.