Memory Corruption Vulnerability in Shared Memory Management of Android Products
CVE-2025-36935

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-36935?

A vulnerability identified in the shared memory management component of Android systems can lead to memory corruption caused by uninitialized data in the function trusty_ffa_mem_reclaim. This flaw allows local applications to potentially escalate privileges, enabling unauthorized access to system resources without requiring user interaction. The issue presents serious security implications for affected devices and highlights the need for timely updates to mitigate risks.

Affected Version(s)

Android Android kernel

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36935 : Memory Corruption Vulnerability in Shared Memory Management of Android Products