← CVE Tracker
7.8HIGH

CVE-2025-32322 — In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a…

Google · Android · Published 4 Sept 2025 · Modified 30 Sept 2026

Description

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

What to do
  1. Check whether Android is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-32322