CVE-2025-26450

7.8

Google · Android

A missing permission check in the Android IInputMethodSessionWrapper allows an untrusted application to inject key and motion events, potentially leading to local privilege escalation.

Executive summary

A critical vulnerability in the Android Input Method Framework allows local applications to escalate privileges by injecting unauthorized input events.

Vulnerability

This is an elevation of privilege vulnerability caused by a missing permission check within the IInputMethodSessionWrapper component. An untrusted application can exploit this flaw to inject malicious key and motion events into the system default input method editor without requiring user interaction or elevated privileges.

Business impact

The ability for a malicious local application to escalate privileges poses a significant threat to device integrity and user data confidentiality. Because this vulnerability allows an attacker to bypass standard input restrictions, it could facilitate unauthorized actions, data theft, or complete system compromise. With a CVSS score of 7.8, this flaw represents a high risk to all affected Android environments.

Remediation

Immediate Action: Organizations should ensure that all Android devices are updated to the security patch level specified in the June 2025 Android Security Bulletin.

Proactive Monitoring: Security teams should monitor mobile device management logs for suspicious application behavior or unexpected privilege escalation attempts on managed handsets.

Compensating Controls: Enforce strict application vetting processes and utilize mobile threat defense solutions to detect and block malicious applications that may attempt to leverage local exploits.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of this privilege escalation flaw, immediate deployment of the June 2025 Android security patches is essential. Administrators must prioritize updating devices running Android 13, 14, and 15 to prevent potential local exploitation by malicious software.

More Google CVEs

Sources