
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-32350 is a tapjacking/overlay vulnerability in Android that allows a local attacker to escalate privileges without requiring additional execution privileges or user interaction. The flaw exists in the maybeShowDialog function of ControlsSettingsDialogManager.kt, where the ControlsSettingsDialog can be overlaid by a malicious application. Affected versions include Android 14.0, 15.0, and 16.0. It was publicly disclosed on September 4, 2025, with a patch included in the September 2025 Android Security Bulletin. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).
The root cause is classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), a class of weakness commonly associated with tapjacking and overlay attacks (CAPEC-506, CAPEC-103). In the vulnerable code path, maybeShowDialog in ControlsSettingsDialogManager.kt does not adequately restrict which UI layers can be rendered on top of the ControlsSettingsDialog, allowing a malicious app to overlay a deceptive interface and capture user interactions intended for the legitimate dialog. The attack vector is local (the attacker must have a low-privileged app installed on the device), and no user interaction is required for exploitation. A patch commit is available in the Android platform frameworks/base repository (Android Security Bulletin, AOSP Commit).
Successful exploitation allows a local attacker to escalate privileges on the affected Android device without needing elevated permissions to begin with. This could enable unauthorized access to system-level resources, execution of actions with higher-level system permissions, and potential compromise of the device's overall security model. Confidentiality, integrity, and availability are all rated as High impact, meaning an attacker could read sensitive data, modify system state, or disrupt device functionality (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Security Bulletin).
maybeShowDialog in ControlsSettingsDialogManager.kt to display the ControlsSettingsDialog on the target device.ControlsSettingsDialog, intercepting or manipulating user interactions intended for the legitimate dialog.SYSTEM_ALERT_WINDOW or overlay permissions on the device.logcat) showing unexpected overlay window creation events coinciding with ControlsSettingsDialog display events.Google has released a patch as part of the September 2025 Android Security Bulletin (security patch level 2025-09-01). Users and administrators should apply the September 2025 Android security update to all affected devices running Android 14, 15, or 16 as soon as it becomes available from their device manufacturer. As a general workaround, users should avoid installing applications from untrusted sources and review app permissions, particularly those requesting overlay (SYSTEM_ALERT_WINDOW) or accessibility permissions (Android Security Bulletin).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in the September 2025 Android OS update, including this issue, and highlighted the potential for privilege escalation (CIS Advisory). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."