CVE-2025-26455
7.8Google · Android
A heap buffer overflow in NdkMediaCodec.cpp allows a local attacker to escalate privileges without requiring user interaction.
Executive summary
A heap buffer overflow vulnerability in the Android NdkMediaCodec component poses a significant risk of local privilege escalation for affected devices.
Vulnerability
This vulnerability is a heap buffer overflow occurring within multiple functions of NdkMediaCodec.cpp. The flaw allows an attacker with local, low-privileged access to escalate their permissions on the device without requiring user interaction.
Business impact
The ability for a local attacker to escalate privileges to a higher level of authority constitutes a severe security breach. With a CVSS score of 7.8, this vulnerability represents a high risk, as it could allow unauthorized access to sensitive user data, bypass security controls, or facilitate the installation of persistent malicious software.
Remediation
Immediate Action: Apply the June 2025 Android security updates provided by the device manufacturer immediately.
Proactive Monitoring: Monitor device system logs for unexpected crashes or errors related to the NdkMediaCodec component, which may indicate exploitation attempts.
Compensating Controls: Ensure that third-party applications are installed only from trusted sources and that security policies restricting unauthorized app installation are strictly enforced.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete privilege escalation, this vulnerability must be treated with high priority. System administrators and users should verify that their devices have received the June 2025 security patches to mitigate this heap buffer overflow risk. Immediate application of vendor-supplied firmware updates is the only effective way to remediate this flaw.