cbcvebase.
CVE-2025-22429
published 2025-09-02

CVE-2025-22429: In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.24%
14.6th percentile
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformframeworks_base>= 13:0 < 13:2025-04-0113:2025-04-01
platformframeworks_base>= 14:0 < 14:2025-04-0114:2025-04-01
platformframeworks_base>= 15-next:0 < 15-next:2025-04-0115-next:2025-04-01
platformframeworks_base>= 15:0 < 15:2025-04-0115:2025-04-01

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-22429 is a local privilege escalation vulnerability (no additional privileges required, no user interaction) affecting Android versions 13, 14, and 15. Detection should focus on unexpected privilege escalation events on Android devices running these versions.
  • Track Android Security Bulletin patch level 2025-04-01 on managed devices; unpatched Android 13, 14, and 15 devices are vulnerable to this critical local EoP (type: ID — Information Disclosure/EoP). Ensure devices report a security patch level of 2025-04-01 or later.
  • ·The vulnerability is classified as type 'ID' (likely Information Disclosure or Incorrect Default) with CRITICAL severity, but the NVD description characterizes it as arbitrary code execution leading to local privilege escalation. The exact vulnerable component is not publicly disclosed in these sources; the internal Android bug tracker reference is A-373357090.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.