← CVE Tracker
7.8HIGH

CVE-2025-32347 — In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location…

Google · Android · Published 4 Sept 2025 · Modified 1 Oct 2026

Description

In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

References

What to do
  1. Check whether Android is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-32347