2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-32345HIGH7.8In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa...
CVE-2025-32333HIGH7.8In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th...
CVE-2025-32332HIGH7.8In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio...
CVE-2025-32331HIGH7.8In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i...
CVE-2025-32330MEDIUM5.7In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio str...
CVE-2025-32327HIGH7.8In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co...
CVE-2025-32326HIGH7.8In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a...
CVE-2025-32325HIGH7.8In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l...
CVE-2025-32324HIGH7.8In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy...
CVE-2025-32323HIGH7.8In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text...
CVE-2025-32321HIGH7.8In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con...
CVE-2025-26464HIGH7.8In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err...
CVE-2025-26454HIGH7.8In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us...
CVE-2025-22441HIGH7.3In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary ja...
CVE-2025-0089HIGH7.8In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could l...
CVE-2025-0076LOW3.3In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check...
CVE-2025-32312HIGH7.8In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified ...
CVE-2025-26463MEDIUM5.5In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This c...
CVE-2025-26462HIGH7.8In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code....
CVE-2025-26458HIGH7.8In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic err...
CVE-2025-26456MEDIUM5.5In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in...
CVE-2025-26455HIGH7.8In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This ...
CVE-2025-26453MEDIUM5.5In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic er...
CVE-2025-26452HIGH7.8In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a ...
CVE-2025-26450HIGH7.8In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now