CVE-2025-26426: Input Validation
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26426?
CVE-2025-26426 has a high severity rating due to its potential for local escalation of privilege.
How do I fix CVE-2025-26426?
To remediate CVE-2025-26426, ensure that your Android OS is updated to the latest security patch that addresses this vulnerability.
Who is affected by CVE-2025-26426?
CVE-2025-26426 affects devices running the Android OS that utilize the vulnerable BroadcastController.java functionality.
What could exploit CVE-2025-26426?
CVE-2025-26426 could be exploited by a local attacker to receive broadcasts intended for the "android" package, thus leading to possible privilege escalation.
Is user interaction required to exploit CVE-2025-26426?
No, CVE-2025-26426 can be exploited without any user interaction, making it particularly concerning.