Junglewise Threat Intelligence

CVE-2025-32348: Google Android Framework privilege escalation via background activity launch

CVE-2025-32348 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's Framework component could allow a malicious application to launch background activities without the necessary permissions. This could lead to an unauthorized escalation of privileges, potentially allowing an attacker to perform actions or access data they should not have access to. No user interaction is required for this exploit to occur.

Technical details

A vulnerability in multiple locations within the Android Framework component arises from a missing permission check. This flaw allows a local attacker to trigger background activity launches without the required authorization. Exploitation does not require additional execution privileges or user interaction. The vulnerability can lead to local escalation of privilege (EoP) or denial of service (DoS) depending on the specific implementation context. Patches are available in the June 2026 Android Security Bulletin for AOSP versions 14, 15, 16, and 16-qpr2.

Affected products

  • Google Android Framework 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin
  • 2026-06-01: patched: Security patch levels of 2026-06-05 or later address this issue

References

Related threats