Android Skia Out-of-Bounds Write Vulnerability in BMP Codec Allowing Privilege Escalation

Vulnerability

A heap buffer overflow vulnerability has been identified in the Skia library's BMP standard codec, specifically in the 'initializeSwizzler' function. This vulnerability allows for an out-of-bounds write, which could be exploited to escalate privileges remotely, without requiring any additional execution privileges or user interaction. The issue affects Android devices with the April 2025 security patch level.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation on the affected device.

Remediation

Users can update their devices to the April 2025 security patch level or later to address this vulnerability.

Added: Sep 2, 2025, 11:19 PM
Updated: Sep 2, 2025, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
5.3
remediation
7.7
relevance
0.5
threat
3.3
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.