cbcvebase.
CVE-2025-32324
published 2025-09-04

CVE-2025-32324: In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

16 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
msrcazl3_cups_2.3.3op2-6_on_azure_linux_3.0
msrcazl3_cups_2.4.10-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cups_2.3.3op2-7_on_cbl_mariner_2.0
msrccbl2_cups_2.3.3op2-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
platformframeworks_base>= 15:0 < 15:2025-09-0115:2025-09-01
platformframeworks_base>= 16-next:0 < 16-next:2025-09-0116-next:2025-09-01
platformframeworks_base>= 16:0 < 16:2025-09-0116:2025-09-01