CVE-2025-32320

7.8

Google · Android

A confused deputy vulnerability in Android System UI allows for unauthorized access to images belonging to other users, potentially leading to local privilege escalation.

Executive summary

A vulnerability in the Android System UI could allow a local attacker to bypass access controls and view images belonging to other users without requiring user interaction.

Vulnerability

This is a confused deputy vulnerability occurring within the System UI component. The flaw allows for local escalation of privilege, enabling an attacker with local access to compromise confidentiality and integrity without requiring additional execution privileges or user interaction.

Business impact

The ability for a local attacker to access another user's private images poses a significant privacy and security risk. Given the CVSS score of 7.8, this vulnerability is considered High severity, as it facilitates unauthorized data access and potential system-wide compromise on affected mobile devices.

Remediation

Immediate Action: Prioritize the installation of the latest Android security patches provided by the device manufacturer or Google as soon as they become available.

Proactive Monitoring: Monitor device access logs and look for unauthorized attempts to access system-level UI components or unusual photo gallery activity.

Compensating Controls: Ensure that device-level security features such as File-Based Encryption and managed work profiles are active to limit the reach of an attacker during a local compromise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant local privilege escalation risk that could lead to the exposure of sensitive user data. It is imperative that administrators track the release of Android security updates and deploy them to all managed endpoints immediately upon availability to mitigate the risk of unauthorized data access.

More Google CVEs

Sources