Android Framework Information Disclosure Vulnerability in Wallet Component

Vulnerability

A vulnerability allowing unauthorized access to another user's icons has been identified in the Android Framework. This issue arises from a missing permission check, which could lead to local information disclosure without requiring additional execution privileges or user interaction. The vulnerability affects multiple versions of the Android Framework.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information, specifically icons belonging to other users, within the affected component of the Android Framework.

Reproduction

The vulnerability can be reproduced by accessing the wallet component in the Android Framework. Due to the missing permission check, it is possible to view icons that belong to another user.

Remediation

Users can update their devices to the September 2025 security patch level to address this vulnerability.

Added: Sep 4, 2025, 7:52 PM
Updated: Sep 4, 2025, 7:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.7
remediation
0.0
relevance
0.5
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.