CVE-2025-26452: Elevation of privilege in Google Android
In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-26452: Elevation of privilege in Google Android
Description
In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- google_android
- Date Reserved
- 2025-02-10T18:29:43.944Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 68b9ccbad6fd7c5a76c5d899
Added to database: 9/4/2025, 5:30:34 PM
Last updated: 9/4/2025, 5:30:34 PM
Views: 1
Related Threats
CVE-2025-32312: Elevation of privilege in Google Android
HighCVE-2025-26463: Denial of service in Google Android
HighCVE-2025-26462: Elevation of privilege in Google Android
UnknownCVE-2025-26458: Elevation of privilege in Google Android
UnknownCVE-2025-26456: Denial of service in Google Android
UnknownActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.