CVE-2025-22420

7.8

Google · Android

A confused deputy vulnerability in Android allows unauthorized access to audio files across user profiles, potentially leading to local privilege escalation.

Executive summary

A critical local privilege escalation flaw in Android versions 13 through 16 permits unauthorized access to sensitive audio data across user profiles without requiring user interaction.

Vulnerability

The vulnerability stems from a confused deputy flaw that allows an attacker with local, low-privileged access to bypass security boundaries and access audio files belonging to other user profiles. Exploitation does not require user interaction or elevated permissions.

Business impact

The ability to access private audio files across user profiles presents a significant threat to user privacy and data confidentiality. Given the CVSS score of 7.8, this high-severity flaw could be leveraged to extract sensitive information or facilitate further unauthorized system actions, potentially compromising the integrity of multi-user environments.

Remediation

Immediate Action: Apply the security updates provided in the December 2025 Android Security Bulletin to all affected devices.

Proactive Monitoring: Review system logs for unauthorized attempts to access protected media storage or unexpected cross-profile file system activity.

Compensating Controls: Ensure that third-party applications are restricted from unnecessary file system permissions and maintain strict control over user profile creation on managed devices.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a serious risk to data isolation within the Android ecosystem. Organizations and individual users should prioritize the deployment of the December 2025 security patches to prevent potential privilege escalation and unauthorized data access. Failure to patch leaves devices susceptible to local attackers seeking to harvest private audio recordings.

More Google CVEs

Sources