CVE-2025-22414
7.8Google · Android
A missing permission check in the FrpBypassAlertActivity component of Android allows for a local elevation of privilege without requiring user interaction.
Executive summary
A vulnerability in the Android Factory Reset Protection (FRP) mechanism enables local attackers to elevate privileges on versions 13 and 14, posing a significant risk to device security.
Vulnerability
This elevation of privilege vulnerability exists within the FrpBypassAlertActivity component due to a missing permission check, allowing a local attacker to bypass Factory Reset Protection without user interaction.
Business impact
The ability for a local attacker to elevate privileges on an Android device threatens the integrity of the entire mobile security model. This flaw could allow unauthorized access to protected data or bypass security controls intended to prevent device theft, resulting in potential data loss or unauthorized device control. Given the high CVSS score of 7.8, this is considered a high-severity issue that requires prompt mitigation.
Remediation
Immediate Action: Review the latest Google Android Security Bulletin for the relevant device hardware and apply the necessary manufacturer-provided security patches.
Proactive Monitoring: Monitor device logs for anomalous activity related to system-level permissions or unexpected triggers of the Factory Reset Protection interface.
Compensating Controls: Ensure that devices are managed via an enterprise mobility management (EMM) solution that enforces strict device locking policies and prohibits unauthorized local access.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
This vulnerability represents a significant security risk for Android devices running versions 13 and 14. IT and security teams should prioritize the deployment of vendor-supplied security updates as soon as they become available for their specific device models to neutralize the risk of unauthorized privilege escalation.