Android Telephony Framework Local Privilege Escalation Vulnerability
Vulnerability
A local elevation of privilege vulnerability has been identified in the Android Telephony framework. The issue arises from improper locking in the CommandParamsFactory.java file, which allows for unintended browser interactions from the lock screen. This vulnerability could lead to physical escalation of privileges without requiring additional execution rights or user interaction.
Impact
Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.
Remediation
Users can update their devices to the December 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
