In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://android.googlesource.com/platform/packages/modules/IntentResolver/+/923a5673ac9d4b366097a8912a04e40e85111ed4 | Patch Product |
| https://source.android.com/security/bulletin/2025-09-01 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-04 19:15
Updated : 2025-09-05 19:15
NVD link : CVE-2025-48526
Mitre link : CVE-2025-48526
CVE.ORG link : CVE-2025-48526
JSON object : View
Products Affected
- android
CWE
CWE-266
Incorrect Privilege Assignment
