CVE-2025-26444
7.8Google · Android
A logic error in VoiceInteractionManagerService.java allows a local attacker to escalate privileges by forcing the system to revert to the default assistant application.
Executive summary
A local elevation of privilege vulnerability in Google Android 13 and 14 allows an attacker to gain unauthorized assistant roles without user interaction.
Vulnerability
The vulnerability resides in the onHandleForceStop function within VoiceInteractionManagerService.java, where a logic error causes the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped. This grants the default assistant application the ROLE_ASSISTANT, which can be triggered by a local attacker with low privileges.
Business impact
This flaw carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows a malicious local application to elevate its privileges to the assistant role, potentially leading to unauthorized access to user data and system functionality, which compromises the integrity and confidentiality of the mobile device.
Remediation
Immediate Action: Update affected Android devices to the latest security patch level as specified in the May 2025 Android Security Bulletin.
Proactive Monitoring: Monitor system logs for unexpected changes in the active assistant application or unauthorized attempts to force-stop system-level services.
Compensating Controls: Since this is a local privilege escalation, ensure that users only install applications from trusted sources to minimize the risk of malicious software gaining the initial local access required to trigger this exploit.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this elevation of privilege vulnerability necessitates prompt attention from security administrators and Android device users. Organizations should prioritize the deployment of the May 2025 Android security updates to all managed devices to neutralize this risk and prevent unauthorized escalation of privileges.