CVE-2025-32347: High severity Google Android vulnerability
Published Sep 2, 2025
·Updated
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
5 affected components
Google Android
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android=16.0
Remediation
Event History
Sep 2, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 4, 2025
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32347?
CVE-2025-32347 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-32347?
To fix CVE-2025-32347, ensure that your Android device is updated to the latest security patch provided by Google.
3
What devices are affected by CVE-2025-32347?
CVE-2025-32347 affects devices running certain versions of Google Android operating systems.
4
What impact does CVE-2025-32347 have on users?
CVE-2025-32347 can potentially allow local escalation of privilege, impacting user data and privacy.
5
Is user interaction needed to exploit CVE-2025-32347?
Yes, user interaction is required for the exploitation of CVE-2025-32347.