Android Print Manager Service Cross-User Image Leak Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability has been identified in the Print Manager Service component of Android, specifically in the validateIconUserBoundary function. This issue arises from a confused deputy problem, leading to a potential cross-user image leak. Exploitation of this vulnerability could result in local privilege escalation, with no additional execution privileges required. User interaction is not necessary for exploitation. The vulnerability affects Android versions 13, 14, 15, and 16.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user images across different accounts, potentially allowing for misuse of this information. Additionally, it could facilitate local privilege escalation, enabling a user to gain elevated rights or access within the system.

Reproduction

To reproduce this vulnerability, a specially crafted URI can be used to trick the system into leaking image data from one user to another. This can be done by manipulating the URI to include incorrect user information, which the Print Manager Service will then process, leading to the unintended image leak.

Remediation

Users can update their devices to the December 2025 security patch level to address this vulnerability.

Added: Dec 8, 2025, 5:29 PM
Updated: Dec 8, 2025, 6:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.7
remediation
0.0
relevance
1.3
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.