Android Framework Companion Device Notification Access Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability has been identified in the Android Framework's DisassociationProcessor component, specifically within the notification management for companion devices. Due to inadequate input validation, an application may improperly retain access to notifications even when it is not connected to a companion device. This flaw could facilitate a local escalation of privileges, as no additional execution rights are required for exploitation. Notably, user interaction is also unnecessary.

Impact

Exploitation of this vulnerability could lead to unauthorized access to notification data, potentially allowing an application to escalate its privileges on the device.

Remediation

Users can update their devices to the December 2025 security patch level to address this vulnerability.

Added: Dec 8, 2025, 6:00 PM
Updated: Dec 8, 2025, 9:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.3
remediation
0.0
relevance
1.3
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.