Memory Overwrite Vulnerability in Android Devices by Google
CVE-2025-36932

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-36932?

A vulnerability exists in the tracepoint_msg_handler function within the tracepoint IPC component of Google's Android operating system. This flaw is caused by improper input validation, potentially allowing attackers to overwrite memory. Exploiting this vulnerability could permit local privilege escalation without requiring additional execution privileges or user interaction, making it a significant security concern for affected devices.

Affected Version(s)

Android Android kernel

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36932 : Memory Overwrite Vulnerability in Android Devices by Google