CVE-2025-0080

7.8

Google · Android

A tapjacking vulnerability in Android 15 allows attackers to overlay the installation confirmation dialog, potentially leading to local privilege escalation without requiring user interaction.

Executive summary

A critical local elevation of privilege vulnerability in Android 15 allows attackers to bypass security dialogs via tapjacking, necessitating immediate security updates.

Vulnerability

This vulnerability involves a tapjacking or overlay attack where an attacker can obscure the installation confirmation dialog. The flaw allows for local escalation of privilege, and it is notable that the attack does not require user interaction or additional execution privileges.

Business impact

The ability to escalate privileges locally on a device poses a significant risk to the integrity and confidentiality of the entire mobile environment. Given the CVSS score of 7.8, this flaw is categorized as High severity, as it could allow an attacker to gain unauthorized control over device functions or sensitive data, potentially bypassing critical security gates meant to protect the operating system.

Remediation

Immediate Action: Apply the March 2025 Android security updates provided by Google or your specific device manufacturer to patch this vulnerability.

Proactive Monitoring: Monitor device logs for unusual application behavior or unexpected overlays that appear during installation processes.

Compensating Controls: Ensure that users only install applications from trusted, verified sources such as the official Google Play Store to reduce the likelihood of encountering malicious applications that could leverage this exploit.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the fact that it requires no user interaction to trigger, necessitates immediate action. Organizations managing Android 15 deployments must prioritize the deployment of the March 2025 security bulletin to ensure that the overlay protection mechanisms are correctly implemented and that the privilege escalation vector is closed.

More Google CVEs

Sources