In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
Configuration 1 (hide)
|
History
04 Sep 2025, 16:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Google android
|
|
References | () https://android.googlesource.com/platform/packages/apps/Settings/+/ad9fb985df470bed5f77da4701f2aebe45af5ff3 - Product | |
References | () https://source.android.com/security/bulletin/2025-04-01 - Vendor Advisory | |
CPE | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
03 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-441 |
02 Sep 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 23:15
Updated : 2025-09-04 16:39
NVD link : CVE-2025-22418
Mitre link : CVE-2025-22418
CVE.ORG link : CVE-2025-22418
JSON object : View
Products Affected
- android
CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')