In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
Configuration 1 (hide)
|
History
02 Sep 2025, 18:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://android.googlesource.com/platform/frameworks/base/+/7ba8c8f63f1b13b127c871749314a242ff022ae2 - Product | |
References | () https://android.googlesource.com/platform/packages/services/Telecomm/+/685c2fc2f6b40bb2113db77da270c7b7220791c4 - Product | |
References | () https://source.android.com/security/bulletin/2025-03-01 - Vendor Advisory | |
First Time |
Google android
|
|
CPE | cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
27 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.0 |
CWE | CWE-116 |
26 Aug 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-26 23:15
Updated : 2025-09-02 18:03
NVD link : CVE-2025-0083
Mitre link : CVE-2025-0083
CVE.ORG link : CVE-2025-0083
JSON object : View
Products Affected
- android
CWE
CWE-116
Improper Encoding or Escaping of Output