CVE-2025-32333

7.8

Google · Android

A logic error in the SpaActivity component of Android 14 allows for a local cross-user permission bypass, potentially leading to unauthorized privilege escalation.

Executive summary

A critical local privilege escalation vulnerability in Android 14 allows a local attacker to bypass cross-user permissions without requiring user interaction.

Vulnerability

The vulnerability exists within the startSpaActivityForApp function of SpaActivity.kt, where a logic error enables a cross-user permission bypass. This flaw allows a local, low-privileged attacker to escalate privileges on the device without requiring user interaction.

Business impact

The ability for a local attacker to escalate privileges to a higher level poses a significant risk to the confidentiality, integrity, and availability of sensitive user data stored on the mobile device. Given the CVSS score of 7.8, this vulnerability is classified as High severity. Unauthorized access to system-level functions can result in complete device compromise, potentially exposing enterprise data if the device is managed under a Bring Your Own Device or corporate mobility policy.

Remediation

Immediate Action: Apply the September 2025 Android Security Bulletin updates provided by Google or your specific device manufacturer immediately.

Proactive Monitoring: Security teams should audit device logs for unusual activity or unauthorized attempts to access protected system settings or cross-user application data.

Compensating Controls: Ensure that all applications are sourced from trusted app stores and maintain strict device management policies to minimize the potential for malicious local applications to be installed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk for users running Android 14, as it permits an attacker to bypass critical security boundaries. Organizations should prioritize the deployment of the September 2025 security patch across their mobile fleet to neutralize this escalation path and protect against potential local exploitation.

More Google CVEs

Sources