CVE-2025-26428: Low severity Google Android vulnerability
In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26428?
CVE-2025-26428 has a severity level that allows for physical escalation of privilege without requiring additional execution privileges.
How do I fix CVE-2025-26428?
To fix CVE-2025-26428, update your affected Android device to the latest security patch provided by Google.
What devices are affected by CVE-2025-26428?
CVE-2025-26428 affects devices running specific versions of Google Android that contain the vulnerable 'startLockTaskMode' function.
Can CVE-2025-26428 be exploited remotely?
No, CVE-2025-26428 requires user interaction for exploitation, making it a physical security risk.
What should I do if I suspect exploitation of CVE-2025-26428?
If you suspect exploitation of CVE-2025-26428, it's crucial to change your device security settings and apply available updates immediately.