Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-26425

In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.2%
CVSS Severity
CVSS v3 Score 4.0
Products affected by CVE-2025-26425
  • Google » Android » Version: 14.0
    cpe:2.3:o:google:android:14.0
  • Google » Android » Version: 15.0
    cpe:2.3:o:google:android:15.0


Contact Us

Shodan ® - All rights reserved