In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation in Android Image Handling Enables Local Privilege Escalation | |
| Weaknesses | CWE-264 CWE-732 |
Wed, 03 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
ssvc
|
Wed, 03 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Input Validation in Android Image Handling Enables Local Privilege Escalation | |
| Weaknesses | CWE-264 CWE-732 |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android Image Disclosure and Privilege Escalation via Improper Input Validation | |
| Weaknesses | CWE-20 CWE-200 CWE-284 |
Tue, 02 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android Image Disclosure and Privilege Escalation via Improper Input Validation | |
| Weaknesses | CWE-20 CWE-200 CWE-284 |
Mon, 01 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android |
|
| Vendors & Products |
Google
Google android |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published: 2026-06-01T21:14:48.951Z
Updated: 2026-06-03T20:23:50.316Z
Reserved: 2025-01-06T17:45:03.361Z
Link: CVE-2025-22424
Updated: 2026-06-03T20:21:19.426Z
Status : Modified
Published: 2026-06-01T22:16:17.397
Modified: 2026-06-03T22:16:33.977
Link: CVE-2025-22424
No data.