CVE-2025-26458
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected (3)
References (2)
https://android.googlesource.com/platform/frameworks/base/+/9d2acb2d3c5dae5ace5add3e1d0c0e3ab5cfb900
Source: security@android.com
PatchProduct
Timeline
No history available yet.