
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-32333 is a local privilege escalation vulnerability in Android 14.0 caused by a logic error in startSpaActivityForApp within SpaActivity.kt (Settings app). The flaw enables a cross-user permission bypass, allowing a low-privileged local attacker to escalate privileges without any user interaction. It was disclosed as part of Google's September 2025 Android Security Bulletin (published September 4, 2025) and carries a CVSS v3.1 base score of 7.8 (High), classified under CWE-863 (Incorrect Authorization) (Android Bulletin).
The root cause is a logic error in the startSpaActivityForApp method of SpaActivity.kt within the Android Settings application, classified as CWE-863 (Incorrect Authorization). This error allows an attacker to bypass cross-user permission checks, enabling unauthorized access to activities or data belonging to other user profiles on the same device. Exploitation requires only low-level local privileges (e.g., a malicious app installed on the device) and no user interaction. A patch was committed to the Android Open Source Project (AOSP) repository for the Settings package (Android Bulletin, AOSP Patch).
Successful exploitation allows a local attacker to escalate privileges on an Android 14.0 device, bypassing user profile isolation and gaining unauthorized access to data or activities belonging to other user accounts on the same device. This compromises both confidentiality and integrity, as sensitive user data across profiles may be exposed or manipulated. Availability impact is also rated High per the CVSS scoring. The vulnerability is particularly concerning on shared or multi-user Android devices (Android Bulletin).
startSpaActivityForApp method in SpaActivity.kt within the Android Settings application, exploiting the logic error in cross-user permission validation.logcat) showing unexpected cross-user activity launches originating from SpaActivity or startSpaActivityForApp for non-owner user profiles.com.android.settings) from third-party applications, particularly attempts to start activities in the context of a different user profile./data/user/<other_user_id>/) by a low-privilege application.Google released a patch for Android 14.0 as part of the September 2025 Android Security Bulletin (security patch level 2025-09-01). The fix is available via the AOSP commit to the Settings package. Users and administrators should apply the September 2025 security patch immediately through official OEM update channels. No configuration-based workaround is available; patching is the only remediation. Organizations managing Android fleets should verify patch deployment and monitor for unusual cross-user access attempts (Android Bulletin, AOSP Patch).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in the September 2025 Android bulletin, including CVE-2025-32333, highlighting the potential for remote code execution and privilege escalation across the bulletin's scope (CIS Advisory). No significant independent researcher commentary or social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."