CVE-2025-36923

8.0

Google · Android

A heap buffer overflow in the Android kernel's NrmmDecoder component allows for local privilege escalation without user interaction.

Executive summary

A heap buffer overflow vulnerability in the Android kernel, specifically within the NrmmDecoder component, poses a critical risk of privilege escalation to affected devices.

Vulnerability

The vulnerability is a heap buffer overflow located in the NrmmDecoder::DecodeSORTransparentContext function, which allows an adjacent or proximal attacker with low privileges to achieve elevation of privilege. The flaw does not require user interaction to trigger.

Business impact

Successful exploitation of this vulnerability could allow an attacker to gain elevated system privileges, potentially leading to full device compromise. Given the CVSS score of 8.0, this represents a high-severity risk that could result in sensitive data theft, unauthorized system control, and the bypass of security boundaries established by the Android operating system.

Remediation

Immediate Action: Organizations and users should apply the latest Android security patches provided by their device manufacturer as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for unusual process crashes or signs of unauthorized system-level activity that may indicate an exploitation attempt.

Compensating Controls: Ensure that Google Play Protect is enabled and that devices are kept in a restricted state, avoiding the installation of applications from untrusted sources to limit the initial access vector.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant security risk to Android devices by allowing for kernel-level privilege escalation. It is imperative that administrators and users prioritize the installation of firmware updates issued by Google or the respective device OEMs to address the underlying heap buffer overflow and mitigate the potential for system compromise.

More Google CVEs

Sources