CVE-2025-22432: Input Validation
In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22432?
CVE-2025-22432 has a high severity rating due to the potential for local escalation of privilege.
How do I fix CVE-2025-22432?
To fix CVE-2025-22432, update your Android device to the latest software version that mitigates this vulnerability.
Which versions of Android are affected by CVE-2025-22432?
CVE-2025-22432 affects Android versions 13.0, 14.0, 15.0, and 16.0.
What type of exploitation is possible with CVE-2025-22432?
CVE-2025-22432 can be exploited to run background activities with user execution privileges without user interaction.
Is user interaction required for the exploitation of CVE-2025-22432?
No, user interaction is not needed for the exploitation of CVE-2025-22432.