Out of Bounds Write Vulnerability in Android Pixel Devices
CVE-2025-36897

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-36897?

A critical coding oversight in cd_CnMsgCodecUserApi.cpp allows for an out of bounds write. This vulnerability can potentially be exploited to execute arbitrary code remotely without requiring any user interaction or elevated privileges. As the flaw remains unaddressed, affected users are urged to apply patches and security updates promptly to safeguard their devices.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36897 : Out of Bounds Write Vulnerability in Android Pixel Devices