CVE-2025-32313

8.4

Google · Android

A vulnerability in UsageEvents.java allows for an out of bounds write, potentially leading to local privilege escalation without requiring special permissions or user interaction.

Executive summary

A critical local privilege escalation vulnerability in Google Android versions 14, 15, and 16 presents a significant risk to device security.

Vulnerability

The flaw resides in the UsageEvents.java component, where an incorrect bounds check results in an out of bounds write. This vulnerability can be triggered by an attacker without specific execution privileges or user interaction, enabling local escalation of privilege.

Business impact

The ability for an unprivileged local actor to escalate privileges to a higher level within the Android operating system poses a severe threat to data confidentiality, integrity, and availability. Given the CVSS score of 8.4, this vulnerability is classified as High severity, as it could allow an attacker to bypass security boundaries, access sensitive user data, or gain full control over the compromised device.

Remediation

Immediate Action: Users and administrators should apply the latest security updates provided by Google or their device manufacturer immediately upon availability.

Proactive Monitoring: Security teams should monitor device logs for unusual system service behavior or crashes related to the UsageEvents service.

Compensating Controls: Ensure that Play Protect is enabled and keep device firmware updated to the latest security patch level to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates a prompt response from all stakeholders managing Android devices. Organizations should prioritize the deployment of the March 2026 Android security bulletin updates to mitigate the risk of local privilege escalation. Ensuring that devices are running the latest patched version is the most effective way to eliminate this security gap.

More Google CVEs

Sources