CVE-2025-0081: High severity Google Android vulnerability
Published Mar 3, 2025
·Updated
In dnglosslessdecoder::HuffDecode of dnglosslessjpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Google Android=15.0
Event History
Mar 3, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Aug 26, 2025
CVE Published
via MITRE·10:48 PM
Data Sourced
via MITRE·10:48 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0081?
CVE-2025-0081 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-0081?
To fix CVE-2025-0081, ensure that you update your Google Android software to the latest version that contains the security patch.
3
What causes the vulnerability CVE-2025-0081?
CVE-2025-0081 is caused by uninitialized data in the dng_lossless_decoder::HuffDecode function.
4
Is user interaction required to exploit CVE-2025-0081?
No, user interaction is not needed for the exploitation of CVE-2025-0081.
5
What impact does CVE-2025-0081 have on affected devices?
CVE-2025-0081 could lead to a remote denial of service on affected devices.