Android Voice Interaction Manager Service Assistant Role Mismanagement Vulnerability

Vulnerability

A vulnerability in the Voice Interaction Manager Service can lead to improper handling of assistant applications. When a user-selected assistant is forcefully stopped, the system may mistakenly revert to the default assistant. This issue arises from a logical error in the code, which can result in unauthorized elevation of privileges by automatically granting the default assistant application the ROLE_ASSISTANT, without requiring any additional permissions. Exploitation of this vulnerability does not involve user interaction.

Impact

Exploitation of this vulnerability allows for local escalation of privileges by improperly assigning the ROLE_ASSISTANT to the default assistant application, without the need for additional execution privileges.

Remediation

Users can update their devices to the May 2025 security patch level to address this vulnerability.

Added: Sep 4, 2025, 6:50 PM
Updated: Sep 4, 2025, 6:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.3
remediation
0.0
relevance
0.4
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.