CVE-2025-26464

7.8

Google · Android

A logic error in the AppSearchManagerService component of Android 15 allows for unauthorized background activity launches, resulting in local escalation of privilege.

Executive summary

A critical local privilege escalation vulnerability in Android 15 permits an attacker to gain elevated system access without user interaction.

Vulnerability

The vulnerability resides in the executeAppFunction method within the AppSearchManagerService.java file. It is a logic error that enables a local attacker to trigger a background activity launch, resulting in a full escalation of privilege without requiring user interaction or additional execution permissions.

Business impact

The exploitation of this vulnerability poses a severe risk to mobile device integrity, as it grants an attacker the ability to bypass standard security boundaries to gain elevated privileges. With a CVSS score of 7.8, this flaw represents a high-severity risk that could lead to full system compromise, unauthorized data access, and the potential installation of persistent malicious software on affected devices.

Remediation

Immediate Action: Apply the September 2025 Android security updates provided by Google or your specific device manufacturer immediately.

Proactive Monitoring: Security teams should monitor device logs for unexpected background activity launches or unauthorized service execution patterns originating from the AppSearchManagerService.

Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise-managed devices to detect and block malicious applications that may attempt to leverage this local privilege escalation vector.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

This vulnerability presents a significant security concern for users of Android 15 due to the potential for unauthenticated local privilege escalation. Organizations should prioritize the deployment of the September 2025 security patches across their mobile fleet to mitigate the risk of local device compromise.

More Google CVEs

Sources