Executive brief
A vulnerability in the Android operating system allows malicious applications to bypass security permissions and launch background activities. This could allow an attacker to gain elevated privileges on a mobile device without any interaction from the user. This flaw is reportedly being exploited in the wild, posing a significant risk to user data and device integrity.
Technical details
A privilege escalation vulnerability exists in the Android Framework due to a permissions bypass in multiple locations that allows the launching of activities from the background. The flaw is categorized as a missing authentication for a critical function (CWE-306). An attacker with local access and low privileges can exploit this without any user interaction to achieve a full compromise of confidentiality, integrity, and availability. The vulnerability affects Android versions 13 through 16 and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available through the December 2025 Android Security Bulletin.
Affected products
- Google Android 13.0, 14.0, 15.0, 16.0
Timeline
- 2025-12-01: advisory: Vendor advisory published by Google
- 2025-12-02: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
- 2025-12-08: disclosed: NVD publication date