
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-22421 is a notification content leak vulnerability in Android affecting the contentDescForNotification function in NotificationContentDescription.kt. Due to a logic error in the code, notification content can be exposed through the lockscreen without requiring any additional execution privileges or user interaction. The vulnerability affects Android versions 13.0, 14.0, and 15.0. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).
The root cause is a logic error in NotificationContentDescription.kt within the contentDescForNotification function, classified as CWE-209 (Generation of Error Message Containing Sensitive Information). The flaw causes notification content descriptions to be improperly exposed on the lockscreen, bypassing the intended access controls that should restrict notification visibility when the device is locked. Exploitation requires only low-level local access (e.g., physical access to a locked device or a co-located low-privileged process) and no user interaction, making it straightforward to trigger (Android Security Bulletin).
Successful exploitation results in local information disclosure, specifically the leakage of notification content (which may include messages, emails, authentication codes, or other sensitive data) visible on the lockscreen. There is no impact on integrity or availability. The scope is limited to the affected device, with no direct path to lateral movement, but exposed notification content (e.g., OTP codes or credentials) could facilitate further attacks (Android Security Bulletin).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-22421. The EPSS score is extremely low at approximately 0.009%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was patched as part of the April 2025 Android Security Bulletin (Android Security Bulletin).
Google addressed this vulnerability in the April 2025 Android Security Bulletin (patch level 2025-04-01). Users and administrators should apply the April 2025 or later Android security patch to all affected devices running Android 13, 14, or 15. As a temporary workaround, users can configure their device lockscreen notification settings to hide sensitive notification content (Settings > Notifications > Notifications on lock screen > "Hide silent conversations and notifications" or "Don't show notifications at all") (Android Security Bulletin).
Samsung published its April 2025 security patch details referencing this and over 60 other vulnerabilities fixed in that cycle (Samsung Fans). Huawei also referenced the vulnerability in its June 2025 security details for EMUI (Huawei Central). No notable independent researcher commentary or significant social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."