CVE-2025-32350
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-32350 is a tapjacking/overlay vulnerability in Android that allows a local attacker to escalate privileges without requiring additional execution privileges or user interaction. The flaw exists in the maybeShowDialog function of ControlsSettingsDialogManager.kt, where the ControlsSettingsDialog can be overlaid by a malicious application. Affected versions include Android 14.0, 15.0, and 16.0. It was publicly disclosed on September 4, 2025, with a patch included in the September 2025 Android Security Bulletin. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).

Technical details

The root cause is classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), a class of weakness commonly associated with tapjacking and overlay attacks (CAPEC-506, CAPEC-103). In the vulnerable code path, maybeShowDialog in ControlsSettingsDialogManager.kt does not adequately restrict which UI layers can be rendered on top of the ControlsSettingsDialog, allowing a malicious app to overlay a deceptive interface and capture user interactions intended for the legitimate dialog. The attack vector is local (the attacker must have a low-privileged app installed on the device), and no user interaction is required for exploitation. A patch commit is available in the Android platform frameworks/base repository (Android Security Bulletin, AOSP Commit).

Impact

Successful exploitation allows a local attacker to escalate privileges on the affected Android device without needing elevated permissions to begin with. This could enable unauthorized access to system-level resources, execution of actions with higher-level system permissions, and potential compromise of the device's overall security model. Confidentiality, integrity, and availability are all rated as High impact, meaning an attacker could read sensitive data, modify system state, or disrupt device functionality (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Security Bulletin).

Exploitation steps

  1. Preparation: Develop or obtain a malicious Android application that can be installed on the target device with low-level user privileges (no root required).
  2. Installation: Install the malicious app on the target Android 14, 15, or 16 device, either via social engineering, a third-party app store, or physical access.
  3. Trigger the vulnerable dialog: Wait for or trigger conditions that cause maybeShowDialog in ControlsSettingsDialogManager.kt to display the ControlsSettingsDialog on the target device.
  4. Overlay attack: Use the malicious app to draw a deceptive UI layer (overlay/tapjacking) on top of the ControlsSettingsDialog, intercepting or manipulating user interactions intended for the legitimate dialog.
  5. Privilege escalation: Through the captured interaction, the malicious app gains elevated privileges on the device, enabling access to system-level resources or execution of privileged actions (Android Security Bulletin, AOSP Commit).

Indicators of compromise

  • Process/Application: Presence of an unknown or untrusted application with SYSTEM_ALERT_WINDOW or overlay permissions on the device.
  • Logs: Android system logs (logcat) showing unexpected overlay window creation events coinciding with ControlsSettingsDialog display events.
  • Behavioral: Unexpected privilege changes or system setting modifications not initiated by the device owner; unfamiliar apps appearing with elevated permissions.
  • File System: Presence of APKs from unknown sources in device storage, particularly those requesting overlay or accessibility permissions.

Mitigation and workarounds

Google has released a patch as part of the September 2025 Android Security Bulletin (security patch level 2025-09-01). Users and administrators should apply the September 2025 Android security update to all affected devices running Android 14, 15, or 16 as soon as it becomes available from their device manufacturer. As a general workaround, users should avoid installing applications from untrusted sources and review app permissions, particularly those requesting overlay (SYSTEM_ALERT_WINDOW) or accessibility permissions (Android Security Bulletin).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in the September 2025 Android OS update, including this issue, and highlighted the potential for privilege escalation (CIS Advisory). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management