
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-22425 is a local privilege escalation vulnerability in Android's InstallStart.java (onCreate method) caused by improper input validation, classified as a permissions bypass (CWE-276: Incorrect Default Permissions). It affects Android versions 13.0 and 14.0. The vulnerability was disclosed in Google's Android Security Bulletin dated May 1, 2025, and formally published to NVD on September 4, 2025. It carries a CVSS v3.1 base score of 5.1 (Medium) (Android Bulletin).
The root cause is improper input validation in the onCreate method of InstallStart.java within the Android framework (frameworks/base), classified as CWE-276 (Incorrect Default Permissions). This flaw allows a local attacker to bypass permission checks during the package installation flow, potentially gaining elevated privileges without requiring any additional execution privileges. The attack vector is local, with low attack complexity and no user interaction required per the CVSS scoring, though the ENISA/EUVD description notes user interaction is needed for exploitation — indicating the attacker may need to trigger an installation event. Patch commits are publicly available on the Android source repository (Android Bulletin, AOSP Commit 1, AOSP Commit 2).
Successful exploitation could allow a local attacker to gain unauthorized access to low-level system resources, modify system configurations, and compromise the integrity of the affected Android device. The confidentiality and integrity impacts are rated low, with no availability impact, limiting the scope to partial unauthorized access and modification rather than full system compromise. Lateral movement potential is constrained by the local attack vector, but privilege escalation could serve as a stepping stone for further exploitation on a compromised device (Android Bulletin, ENISA EUVD).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Android Bulletin). The EPSS score is extremely low at 0.000070, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released patches for Android 13.0 and 14.0 as part of the May 2025 Android Security Bulletin (patch level 2025-05-01). Users and administrators should apply the latest Android security updates immediately to affected devices. Two specific patch commits are available in the AOSP frameworks/base repository: commit 8575592 and commit 942884a. As interim measures, restricting local access to critical system components and monitoring for unusual system permission changes is advised (Android Bulletin).
The CIS issued an advisory noting that multiple vulnerabilities in the May 2025 Google Android OS bulletin could allow for remote code execution and privilege escalation, recommending prompt patching (CIS Advisory). Samsung also addressed this CVE in its own May 2025 security update for affected devices. No notable independent researcher commentary or significant social media discussion specific to CVE-2025-22425 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."