CVE-2025-32323: Input Validation
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32323?
CVE-2025-32323 has been rated as a high severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2025-32323?
To fix CVE-2025-32323, update the affected Google Android software to the latest security patch that addresses this vulnerability.
What software versions are affected by CVE-2025-32323?
CVE-2025-32323 affects certain versions of Google Android, specifically those that utilize the vulnerable functionality in Shared.java.
Can CVE-2025-32323 be exploited without user interaction?
No, CVE-2025-32323 requires user interaction to exploit the vulnerability as it involves tricking the user into granting file access.
What is the potential impact of CVE-2025-32323?
The potential impact of CVE-2025-32323 is local escalation of privilege, allowing unauthorized access to files.