Android Input Method Framework Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Android Input Method Framework, specifically within the InputMethodInfo component. This issue arises from a possible resource exhaustion, leading to a local denial-of-service condition. The vulnerability does not require any additional execution privileges and can be exploited without user interaction.

Impact

Exploitation of this vulnerability causes a local denial-of-service condition, where the input method manager runs out of memory while processing excessively large metadata from input method XML files.

Reproduction

The vulnerability can be reproduced by creating a malicious input method that includes an extremely large amount of metadata in its input method XML. When this input method is loaded, the Input Method Manager (IMM) will exhaust system resources, leading to a denial-of-service condition.

Remediation

Users can update to the December 2025 security patch level to address this vulnerability.

Added: Dec 8, 2025, 5:41 PM
Updated: Dec 8, 2025, 6:59 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.7
remediation
0.0
relevance
1.4
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.