CVE-2025-22421
BaseFortify
Publication date: 2025-09-02
Last updated on: 2025-09-04
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 13.0 | |
| android | 15.0 | |
| android | 14.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-209 | The product generates an error message that includes sensitive information about its environment, users, or associated data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a logic error in the contentDescForNotification function of NotificationContentDescription.kt that can cause notification content to be leaked through the lockscreen. It allows local information disclosure without requiring any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of notification content on the lockscreen, potentially exposing sensitive information to anyone with physical access to the device without needing to unlock it or perform any actions.