CVE-2025-32328
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-32328 is a local privilege escalation vulnerability in Android's Session.java that allows a low-privileged user to view images belonging to other users on the same device due to a logic error in the code. It affects Android versions 13.0, 14.0, and 15.0. The vulnerability was disclosed on December 8, 2025, with a patch included in the December 2025 Android Security Bulletin. It carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).

Technical details

The root cause is a logic error (CWE-840 or similar business logic flaw) in multiple functions within Session.java in the Android framework (platform/frameworks/base). The flaw allows a local attacker with low privileges to bypass user isolation controls and access image data belonging to other device users. No additional execution privileges or user interaction are required for exploitation, making this a straightforward local attack. The patch is available in the Android open-source repository (Android AOSP Patch, Android Security Bulletin).

Impact

Successful exploitation allows a low-privileged local attacker to view images belonging to other users on the same Android device, constituting a significant privacy and data exposure risk. The vulnerability has high confidentiality, integrity, and availability impact per its CVSS score, suggesting potential for broader local privilege escalation beyond mere image viewing. Devices running Android 13, 14, and 15 in shared or multi-user configurations are particularly at risk (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000050, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Security Bulletin).

Mitigation and workarounds

Google has released a patch for Android 13.0, 14.0, and 15.0 as part of the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the December 2025 security update immediately. Additionally, restricting physical and local network access to devices, enforcing strong user authentication, and maintaining up-to-date security patch levels are recommended mitigations (Android Security Bulletin, Android AOSP Patch).

Community reactions

The vulnerability received routine coverage as part of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Samsung noted the patch in its October 2025 update coverage, and security aggregators such as BeyondMachines and Hawk-Eye highlighted it in weekly threat digests. No notable independent researcher commentary or significant social media discussion has been identified (Android Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management