CVE-2025-22421
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-22421 is a notification content leak vulnerability in Android affecting the contentDescForNotification function in NotificationContentDescription.kt. Due to a logic error in the code, notification content can be exposed through the lockscreen without requiring any additional execution privileges or user interaction. The vulnerability affects Android versions 13.0, 14.0, and 15.0. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).

Technical details

The root cause is a logic error in NotificationContentDescription.kt within the contentDescForNotification function, classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The flaw causes notification content descriptions to be improperly exposed on the lockscreen, bypassing the intended access controls that should restrict notification visibility when the device is locked. Exploitation requires only low-level local access (e.g., physical access to a locked device or a co-located low-privileged process) and no user interaction, making it straightforward to trigger (Android Security Bulletin).

Impact

Successful exploitation results in local information disclosure, specifically the leakage of notification content (which may include messages, emails, authentication codes, or other sensitive data) visible on the lockscreen. There is no impact on integrity or availability. The scope is limited to the affected device, with no direct path to lateral movement, but exposed notification content (e.g., OTP codes or credentials) could facilitate further attacks (Android Security Bulletin).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-22421. The EPSS score is extremely low at approximately 0.009%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was patched as part of the April 2025 Android Security Bulletin (Android Security Bulletin).

Mitigation and workarounds

Google addressed this vulnerability in the April 2025 Android Security Bulletin (patch level 2025-04-01). Users and administrators should apply the April 2025 or later Android security patch to all affected devices running Android 13, 14, or 15. As a temporary workaround, users can configure their device lockscreen notification settings to hide sensitive notification content (Settings > Notifications > Notifications on lock screen > "Hide silent conversations and notifications" or "Don't show notifications at all") (Android Security Bulletin).

Community reactions

Samsung published its April 2025 security patch details referencing this and over 60 other vulnerabilities fixed in that cycle (Samsung Fans). Huawei also referenced the vulnerability in its June 2025 security details for EMUI (Huawei Central). No notable independent researcher commentary or significant social media discussion has been identified for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management