In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-926 | |
Metrics |
cvssV3_1
|
Fri, 05 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android |
|
Vendors & Products |
Google
Google android |
Thu, 04 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
References |
|

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-09-05T17:21:42.974Z
Reserved: 2025-04-04T23:31:03.897Z
Link: CVE-2025-32347

Updated: 2025-09-05T16:02:35.327Z

Status : Undergoing Analysis
Published: 2025-09-04T19:15:37.437
Modified: 2025-09-05T18:15:41.403
Link: CVE-2025-32347

No data.

Updated: 2025-09-05T14:02:22Z