Out-of-Bounds Read/Write in Lwis IO Buffer of Android Device
CVE-2025-36903

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-36903?

The vulnerability identified in the lwis_io_buffer_write function allows for potential out-of-bounds read and write operations due to inadequate input validation. This security flaw could enable local privilege escalation, with no need for additional execution privileges or user interaction, thereby enhancing the risk of exploitation on affected Android devices.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36903 : Out-of-Bounds Read/Write in Lwis IO Buffer of Android Device