CVE-2025-32345

7.8

Google · Android

A logic error in ContentProtectionTogglePreferenceController.java allows a secondary user to disable the primary user's deceptive app scanning, leading to local privilege escalation.

Executive summary

A vulnerability in the Android ContentProtectionTogglePreferenceController allows a local attacker to escalate privileges by disabling critical security settings for the primary user.

Vulnerability

This is an elevation of privilege vulnerability caused by a logic error in the ContentProtectionTogglePreferenceController.java file. A local secondary user can manipulate the primary user's deceptive app scanning configuration without requiring additional privileges or user interaction.

Business impact

The ability for a secondary user to disable security features like deceptive app scanning significantly degrades the defense-in-depth posture of the Android device. This flaw poses a risk of unauthorized access or the installation of malicious software that would otherwise be blocked, justifying the high severity CVSS score of 7.8.

Remediation

Immediate Action: Apply the September 2025 Android security updates provided by Google to all affected devices.

Proactive Monitoring: Audit system logs for unexpected changes to security preference configurations or unauthorized modifications of user profile settings.

Compensating Controls: Enforce strict device management policies that limit the creation of secondary user accounts on shared or enterprise-managed Android devices.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for local privilege escalation and the bypass of critical security scanning features, administrators should prioritize the deployment of the September 2025 security patch. Immediate action is required to ensure that the security integrity of the primary user profile remains protected against unauthorized changes by secondary users.

More Google CVEs

Sources