Android Framework Elevation of Privilege Vulnerability in VPN Component
Vulnerability
A logic error in the VPN component of the Android Framework allows for a local elevation of privilege by disabling the always-on VPN feature. This vulnerability affects Android versions 13, 14, and 15. Exploitation does not require additional execution privileges or user interaction.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in VPN settings, potentially allowing for data leakage or interception by disabling always-on VPN protections.
Remediation
Users can update to the December 2025 security patch level to address this vulnerability. Instructions for checking and updating Android versions are available on the Google Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
