CVE-2025-0091
published 2025-02-01CVE-2025-0091: Android Security Bulletin 2025-02-01 CVE: CVE-2025-0091 Severity: HIGH Type: EoP Affected AOSP versions: 12, 12L, 13, 14, 15 References: A-366401629
high
Android Security Bulletin 2025-02-01
CVE: CVE-2025-0091
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-366401629
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| platform | packages_apps_settings | >= 12:0 < 12:2025-02-01 | 12:2025-02-01 |
| platform | packages_apps_settings | >= 12L:0 < 12L:2025-02-01 | 12L:2025-02-01 |
| platform | packages_apps_settings | >= 13:0 < 13:2025-02-01 | 13:2025-02-01 |
| platform | packages_apps_settings | >= 14:0 < 14:2025-02-01 | 14:2025-02-01 |
| platform | packages_apps_settings | >= 15-next:0 < 15-next:2025-02-01 | 15-next:2025-02-01 |
| platform | packages_apps_settings | >= 15:0 < 15:2025-02-01 | 15:2025-02-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2025-0091: Android Security Bulletin 2025-02-01
CVE: CVE-2025-0091
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-366401629
vendor_android·2025-02-01
CVE-2025-0091 [HIGH] CVE-2025-0091: Android Security Bulletin 2025-02-01
CVE: CVE-2025-0091
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-366401629
Android Security Bulletin 2025-02-01
CVE: CVE-2025-0091
Severity: HIGH
Type: EoP
Affected AOSP versions: 12, 12L, 13, 14, 15
References: A-366401629
OSV
CVE-2025-0091: In isSafeIntent of AccountManagerService
osv·2025-02-01
CVE-2025-0091 CVE-2025-0091: In isSafeIntent of AccountManagerService
In isSafeIntent of AccountManagerService.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-01
Published