CVE-2025-22409: Use After Free
In rfcsendbufuih of rfctsframes.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22409?
CVE-2025-22409 has a high severity rating due to the potential for arbitrary code execution and local privilege escalation.
How do I fix CVE-2025-22409?
To fix CVE-2025-22409, update your affected Android device to the latest security patch provided by Google.
What causes the CVE-2025-22409 vulnerability?
CVE-2025-22409 is caused by a use after free in the rfc_send_buf_uih function within rfc_ts_frames.cc.
Who is affected by CVE-2025-22409?
CVE-2025-22409 affects devices running specific versions of the Google Android operating system.
Is user interaction necessary for exploiting CVE-2025-22409?
No, user interaction is not needed for the exploitation of CVE-2025-22409.