
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-26462 is a privilege escalation vulnerability in Google Android affecting versions 13.0, 14.0, and 15.0, classified under CWE-269 (Improper Privilege Management). It allows a local attacker with low-level privileges to escalate to higher system privileges without requiring user interaction or additional execution privileges. The vulnerability was addressed in the Google Android Security Bulletin dated June 1, 2025, and was formally published to NVD on September 4, 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Android Bulletin).
The root cause is classified as CWE-269 (Improper Privilege Management), indicating that the Android framework fails to properly enforce privilege boundaries for low-privileged local users. The attack vector is local, requiring only low privileges and no user interaction, suggesting the flaw resides in a system service or framework component accessible to unprivileged apps. A patch was committed to the Android platform frameworks/base repository, pointing to the vulnerability residing in core Android framework code (Android Bulletin, AOSP Patch). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation allows a local attacker to achieve full privilege escalation on the affected Android device, resulting in high confidentiality, integrity, and availability impact. An attacker could gain unauthorized access to sensitive device data, modify system settings, execute privileged system commands, and potentially compromise the overall integrity of the device. The scope is limited to the affected device (unchanged scope), but the impact on that device is severe, potentially enabling persistent access or further malicious activity (Android Bulletin).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of reporting (Android Bulletin). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at approximately 0.009%, reflecting the current absence of observed exploitation activity. The attack requires local access to the device, which limits the attack surface compared to remote vulnerabilities.
Google has released patches for Android versions 13.0, 14.0, and 15.0 as part of the June 2025 Android Security Bulletin (patch level 2025-06-01). Users and administrators should apply the latest Android security patch immediately, prioritizing devices running the affected versions. Samsung has also incorporated these fixes into its June 2025 One UI patch for Galaxy devices, and Huawei addressed related CVEs in its August 2025 EMUI patch (Android Bulletin). As a general mitigation, restrict installation of untrusted applications and enforce strict access controls on managed devices.
Samsung detailed the inclusion of this fix in its June 2025 One UI security patch for Galaxy devices, and Huawei addressed the vulnerability in its August 2025 EMUI patch covering 46 CVEs. Coverage was primarily limited to security news outlets and OEM patch notes, with no notable independent researcher commentary or significant social media discussion identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."