Android Account Type Preference Loader Intent Type Check Bypass Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability has been identified in the AccountTypePreferenceLoader component of the Android Settings app. This issue arises from a confused deputy problem, which creates a potential bypass of intent type checks. As a result, it could lead to unauthorized privilege escalation without requiring additional execution rights or user interaction.

Impact

Exploitation of this vulnerability allows for local privilege escalation, enabling a user to gain elevated rights or access within the system.

Remediation

Users can update their devices to the September 2025 security patch level to address this vulnerability.

Added: Sep 4, 2025, 7:48 PM
Updated: Sep 4, 2025, 7:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.3
remediation
0.0
relevance
0.5
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.