2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58353HIGH8.2Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version...
CVE-2025-32322HIGH7.8In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin...
CVE-2025-26439HIGH7.8In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to b...
CVE-2025-26431HIGH7.8In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility se...
CVE-2025-26419LOW3.3In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This...
CVE-2025-22415MEDIUM4In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local ...
CVE-2025-22414HIGH7.8In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss...
CVE-2025-48581HIGH8.4In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the...
CVE-2025-48563HIGH7.8In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default va...
CVE-2025-48562MEDIUM5In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could...
CVE-2025-48561MEDIUM5.5In multiple locations, there is a possible way to access data displayed on the screen due to side channel information di...
CVE-2025-48560MEDIUM5.5In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could...
CVE-2025-48559MEDIUM5.5In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val...
CVE-2025-48558HIGH7.8In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app ...
CVE-2025-48556HIGH7.3In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper ...
CVE-2025-48554MEDIUM6.1In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a l...
CVE-2025-48553HIGH7.8In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er...
CVE-2025-48552HIGH7.8In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a...
CVE-2025-48551MEDIUM5In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused...
CVE-2025-48550MEDIUM5.5In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav...
CVE-2025-48549HIGH7.8In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T...
CVE-2025-48548HIGH7.3In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva...
CVE-2025-48547HIGH7.3In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead ...
CVE-2025-48546HIGH7.8In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in ...
CVE-2025-48545HIGH7.1In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now