Memory Overwrite Vulnerability in Android Devices by Google
CVE-2025-36932

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-36932?

A vulnerability exists in the tracepoint_msg_handler function within the tracepoint IPC component of Google's Android operating system. This flaw is caused by improper input validation, potentially allowing attackers to overwrite memory. Exploiting this vulnerability could permit local privilege escalation without requiring additional execution privileges or user interaction, making it a significant security concern for affected devices.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36932 : Memory Overwrite Vulnerability in Android Devices by Google