Heap Buffer Overflow Vulnerability in Android Surface Drawing Library
CVE-2025-36907
Currently unrated
What is CVE-2025-36907?
A heap buffer overflow vulnerability exists in the draw_surface_image() function within Android's surface drawing library. This flaw can potentially allow local escalation of privileges when a device's bootloader is unlocked and connected via USB fastboot. Exploitation requires user interaction, making it imperative for users to be aware of their device's security measures.
Affected Version(s)
Android Android kernel