Junglewise Threat Intelligence

CVE-2025-22426: Google Android Framework privilege escalation in ComputerEngine.java

CVE-2025-22426 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A logic error in the Android Framework allows a malicious application to access sensitive data (URIs) belonging to other users on the same device. This could lead to an unauthorized escalation of privileges, potentially allowing an attacker to bypass security boundaries and access private information. No user interaction is required for this exploit to occur.

Technical details

A logic error exists within multiple functions of the ComputerEngine.java component of the Android Framework. This flaw allows a local attacker to access URIs across different user profiles on the same device. The vulnerability is classified as an Elevation of Privilege (EoP) and does not require any special execution privileges or user interaction to exploit. Google has addressed this in the June 2026 Android Security Bulletin for Android versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android Framework 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-01: disclosed: CVE published to NVD dataset

References

Related threats