CVE-2025-22424
Improper Input Validation in Android Leads to Image Exposure
Publication date: 2026-06-01
Last updated on: 2026-06-03
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 14.0 | |
| android | 15.0 | |
| android | 16.0 | |
| android | 16.0 | |
| android | 16.0 | |
| android | 16.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The vulnerability can allow an attacker to access images belonging to other users, potentially exposing private or sensitive information.
It also enables local escalation of privilege, which means an attacker with limited access could gain higher privileges on the affected system.
Can you explain this vulnerability to me?
This vulnerability involves improper input validation in multiple locations, which can allow images to be revealed across different users.
Exploitation requires user interaction and can lead to a local escalation of privilege without needing additional execution privileges.