CVE-2025-32346
7.8Google · Android
A confused deputy vulnerability in the Android VoicemailSettingsActivity component allows for a local work profile contact number leak and potential privilege escalation.
Executive summary
A local privilege escalation vulnerability in Android 16 allows a malicious actor to bypass profile restrictions and access sensitive contact information.
Vulnerability
This vulnerability occurs within the onActivityResult method of VoicemailSettingsActivity.java, where a confused deputy flaw enables local privilege escalation without requiring user interaction or elevated execution privileges.
Business impact
The exploitation of this vulnerability poses a significant risk to data privacy and device integrity. By leaking work profile contact information, an attacker can compromise sensitive enterprise data, while the potential for privilege escalation allows for unauthorized control over system functions. With a CVSS score of 7.8, this flaw is categorized as High severity, necessitating prompt attention to maintain the security posture of mobile endpoints.
Remediation
Immediate Action: Monitor the official Google Android security bulletin for the release of a security patch and deploy it to all affected devices as soon as it becomes available.
Proactive Monitoring: Review system logs for unusual activity related to contact access or unexpected privilege changes within the work profile environment.
Compensating Controls: Enforce strict mobile device management policies that limit the installation of untrusted applications to reduce the likelihood of a local attacker executing the malicious payload.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the High severity rating and the potential for unauthorized access to sensitive work profile data, organizations should prioritize the deployment of the upcoming Android security update. Administrators should verify that all managed devices running Android 16 are prepared for rapid patch application once the vendor releases the specific fix.