2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32345 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa... |
| CVE-2025-32333 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in th... |
| CVE-2025-32332 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalatio... |
| CVE-2025-32331 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error i... |
| CVE-2025-32330 | MEDIUM | 5.7 | 0.1% | Sep 4, 2025 | In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio str... |
| CVE-2025-32327 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This co... |
| CVE-2025-32326 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a... |
| CVE-2025-32325 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to l... |
| CVE-2025-32324 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy... |
| CVE-2025-32323 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text... |
| CVE-2025-32321 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a con... |
| CVE-2025-26464 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic err... |
| CVE-2025-26454 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another us... |
| CVE-2025-22441 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary ja... |
| CVE-2025-0089 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could l... |
| CVE-2025-0076 | LOW | 3.3 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check... |
| CVE-2025-32312 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified ... |
| CVE-2025-26463 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This c... |
| CVE-2025-26462 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code.... |
| CVE-2025-26458 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic err... |
| CVE-2025-26456 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in... |
| CVE-2025-26455 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This ... |
| CVE-2025-26453 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic er... |
| CVE-2025-26452 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a ... |
| CVE-2025-26450 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now