Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23250 | There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 31 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Android
Android android Android tv Google android Tv |
|
| Vendors & Products |
Android
Android android Android tv Google android Tv |
Thu, 31 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Jul 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function. | |
| Title | Race condition in AndroidTV TvSettings | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-07-31T13:20:16.832Z
Reserved: 2025-07-25T08:57:20.782Z
Link: CVE-2025-8192
Updated: 2025-07-31T13:20:12.620Z
Status : Awaiting Analysis
Published: 2025-07-31T09:15:27.827
Modified: 2025-07-31T18:42:37.870
Link: CVE-2025-8192
No data.
OpenCVE Enrichment
Updated: 2025-07-31T20:56:23Z
EUVD