CVE-2025-22425
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-22425 is a local privilege escalation vulnerability in Android's InstallStart.java (onCreate method) caused by improper input validation, classified as a permissions bypass (CWE-276: Incorrect Default Permissions). It affects Android versions 13.0 and 14.0. The vulnerability was disclosed in Google's Android Security Bulletin dated May 1, 2025, and formally published to NVD on September 4, 2025. It carries a CVSS v3.1 base score of 5.1 (Medium) (Android Bulletin).

Technical details

The root cause is improper input validation in the onCreate method of InstallStart.java within the Android framework (frameworks/base), classified as CWE-276 (Incorrect Default Permissions). This flaw allows a local attacker to bypass permission checks during the package installation flow, potentially gaining elevated privileges without requiring any additional execution privileges. The attack vector is local, with low attack complexity and no user interaction required per the CVSS scoring, though the ENISA/EUVD description notes user interaction is needed for exploitation — indicating the attacker may need to trigger an installation event. Patch commits are publicly available on the Android source repository (Android Bulletin, AOSP Commit 1, AOSP Commit 2).

Impact

Successful exploitation could allow a local attacker to gain unauthorized access to low-level system resources, modify system configurations, and compromise the integrity of the affected Android device. The confidentiality and integrity impacts are rated low, with no availability impact, limiting the scope to partial unauthorized access and modification rather than full system compromise. Lateral movement potential is constrained by the local attack vector, but privilege escalation could serve as a stepping stone for further exploitation on a compromised device (Android Bulletin, ENISA EUVD).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Android Bulletin). The EPSS score is extremely low at 0.000070, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Google has released patches for Android 13.0 and 14.0 as part of the May 2025 Android Security Bulletin (patch level 2025-05-01). Users and administrators should apply the latest Android security updates immediately to affected devices. Two specific patch commits are available in the AOSP frameworks/base repository: commit 8575592 and commit 942884a. As interim measures, restricting local access to critical system components and monitoring for unusual system permission changes is advised (Android Bulletin).

Community reactions

The CIS issued an advisory noting that multiple vulnerabilities in the May 2025 Google Android OS bulletin could allow for remote code execution and privilege escalation, recommending prompt patching (CIS Advisory). Samsung also addressed this CVE in its own May 2025 security update for affected devices. No notable independent researcher commentary or significant social media discussion specific to CVE-2025-22425 has been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management